| ▲ | CosmosEscape: Taking over Every Database in Azure Cosmos DB(wiz.io) | |||||||||||||
| 41 points by uvuv 5 hours ago | 11 comments | ||||||||||||||
| ▲ | gtowey an hour ago | parent | next [-] | |||||||||||||
> Cosmos DB's engine translated Gremlin queries into .NET code, enforcing a set of restrictions designed to prevent queries from reaching beyond Gremlin operations. These restrictions, however, didn't sufficiently account for .NET reflection Wow, this is so unbelievably amateurish. | ||||||||||||||
| ▲ | troelsSteegin 4 hours ago | parent | prev | next [-] | |||||||||||||
"Cosmos Master Key"... I can see why that would have been convenient, but talk about a footgun. Right out of a Marvel movie. Still, if admin backdoor access is business-necessary, is the answer a unique admin access key per account? | ||||||||||||||
| ||||||||||||||
| ▲ | lateral_cloud 3 hours ago | parent | prev | next [-] | |||||||||||||
It took them 6 months to fix this properly? | ||||||||||||||
| ||||||||||||||
| ▲ | sakisv 3 hours ago | parent | prev | next [-] | |||||||||||||
Is it me or was there a similar vulnerability reported a few years ago? Something about the attacker getting access to all platform's users' databases, though not sure if it was cosmos or something similar. | ||||||||||||||
| ||||||||||||||
| ▲ | redwood 3 hours ago | parent | prev | next [-] | |||||||||||||
Incredible that this is the second time Wiz has discovered a global Cosmos DB vulnerability (https://chaosdb.wiz.io/) and a shock that anyone is trusting Microsoft, Azure or in particular Cosmos DB with anything mission critical | ||||||||||||||
| ▲ | uvuv 5 hours ago | parent | prev [-] | |||||||||||||
A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database. | ||||||||||||||