ChaosDB explained: Azure's Cosmos DB vulnerability walkthrough
ID: f75e8df5-fab3-5970-887c-733f5420dec6
STIX ID: report--f75e8df5-fab3-5970-887c-733f5420dec6
Feed Name: Wiz Blog
Wiz Research Team disclosed “ChaosDB,” a multi-step chain in Azure Cosmos DB where a misconfigured Jupyter Notebook container (C# host running as root) plus removable container firewall rules allowed access to the host IMDS and WireServer. By querying WireServer and decoding a Certificates Bond Package, researchers obtained internal Microsoft certificates and private keys, decrypted protected extension settings, and retrieved Cosmos DB primary keys, notebook auth tokens, and storage account keys—enabling unauthorized access and administrative control over thousands of customer databases and associated infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
