CosmosEscape, a critical vulnerability in Azure, could have allowed attackers to compromise any database on the Cosmos DB service.
Wiz Research disclosed Wednesday that a chain of vulnerabilities in Azure Cosmos DB's Gremlin query engine — which the firm named CosmosEscape — allowed any attacker with a standard Cosmos DB account ...
Wiz found a “Cosmos Master Key” that could unlock every Azure Cosmos DB database. It is patched, and Wiz’s AI bug-hunter helped find it.
Azure Cosmos DB's Gremlin flaw let Wiz escape the sandbox and retrieve an account key. Microsoft found no unauthorized ...