Critical Flaw Led to Azure Cosmos DB Pwnage
Summary
A critical vulnerability, dubbed CosmosEscape, has been discovered in Azure Cosmos DB. This flaw allowed attackers to gain full read and write access to Cosmos DB accounts by exposing the primary key.
IFF Assessment
This vulnerability allows unauthorized read and write access to sensitive data, posing a significant risk to defenders.
Severity
The vulnerability allows for complete unauthorized read and write access to sensitive data in Azure Cosmos DB, which is critical for many applications. Attackers could exploit this remotely, leading to significant data compromise. The CVSS score is estimated based on the high impact and exploitability described.
Defender Context
This incident highlights the critical importance of securing cloud database credentials and access controls. Defenders should prioritize reviewing and enforcing strict access policies for their cloud databases and remain vigilant for any signs of unauthorized access or data exfiltration.