logo

ChaosDB explained: Azure's Cosmos DB vulnerability walkthrough

ID: f75e8df5-fab3-5970-887c-733f5420dec6

STIX ID: report--f75e8df5-fab3-5970-887c-733f5420dec6

Feed Name: Wiz Blog

Threat Score
95/100

Date Published: 2021-11-11

Date Updated: 2026-05-01

...
...

Wiz Research Team disclosed “ChaosDB,” a multi-step chain in Azure Cosmos DB where a misconfigured Jupyter Notebook container (C# host running as root) plus removable container firewall rules allowed access to the host IMDS and WireServer. By querying WireServer and decoding a Certificates Bond Package, researchers obtained internal Microsoft certificates and private keys, decrypted protected extension settings, and retrieved Cosmos DB primary keys, notebook auth tokens, and storage account keys—enabling unauthorized access and administrative control over thousands of customer databases and associated infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.