Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
ID: 495b5fbb-9865-5fd7-bf65-e32ae28c416d
STIX ID: report--495b5fbb-9865-5fd7-bf65-e32ae28c416d
Feed Name: HackRead
Threat Score
### Executive summary Wiz Research discovered a critical Cosmos DB vulnerability (CosmosEscape) in the Gremlin API that could let an attacker escape the query sandbox, obtain a platform master key, enumerate Cosmos DB instances (including Microsoft internal service databases) and retrieve primary account keys; Microsoft removed the shared master key and deployed mitigations and reports no evidence of customer impact following responsible disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
