ChaosDB: How to discover your vulnerable Azure Cosmos DBs and protect them
ID: 8d47bc50-64c6-524a-88a1-7a0e7e0a8176
STIX ID: report--8d47bc50-64c6-524a-88a1-7a0e7e0a8176
Feed Name: Wiz Blog
Threat Score
Wiz Research disclosed a critical vulnerability named ChaosDB in Azure Cosmos DB where the Jupyter Notebook feature could be abused to obtain other customers' Cosmos DB primary keys and gain full admin access; Microsoft disabled the vulnerable service and the advisory urges immediate key rotation, network hardening, and migration to RBAC, while providing detection and remediation guidance and scripts for customers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
