Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

Summary

A vulnerability in Azure Cosmos DB, dubbed CosmosEscape by Wiz, could have allowed attackers to escape the Gremlin query sandbox and gain full read/write access to customer databases. The exploit chain began with a specially crafted query against an attacker-controlled Gremlin database.

IFF Assessment

FOE

This vulnerability represents a significant risk to defenders as it allowed for broad access to sensitive customer data within Azure Cosmos DB.

Severity

9.0 Critical (AI Estimated)

The vulnerability allowed for remote code execution and broad access to sensitive data across tenants, with high exploitability due to the nature of the query sandbox escape.

Defender Context

This incident highlights the critical importance of robust security testing and prompt patching for cloud database services. Defenders should monitor for any indicators of compromise related to Azure Cosmos DB and ensure all systems are updated to the latest patched versions.

Read Full Story →