Interestana
Home/News/Azure Cosmos DB Flaw Exposed Platform-Wide Key
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Azure Cosmos DB Flaw Exposed Platform-Wide Key

Azure Cosmos DB Flaw Exposed Platform-Wide Key

A critical vulnerability in Microsoft's Azure Cosmos DB, identified and patched by cloud security firm Wiz, could have allowed attackers to gain unrestricted read and write access to any customer database hosted on the platform. Wiz, which codenamed the exploit chain CosmosEscape, detailed in a blog post that the vulnerability stemmed from the ability to escape the Gremlin query sandbox. This escape would have granted an attacker the capability to obtain a platform-wide key, effectively providing access to all databases across different customer tenants.

The exploit chain reportedly began with a specially crafted query directed at a Gremlin database under the attacker's control. Successful execution of this query would have enabled code execution on the underlying infrastructure. From this compromised position, an attacker could then leverage the vulnerability to access sensitive data and potentially modify or delete information within any Azure Cosmos DB instance. The Gremlin API is a graph traversal language used for querying Apache TinkerPop-enabled graph databases, and Azure Cosmos DB offers a Gremlin API as one of its multi-model database interfaces.

Wiz reported that the vulnerability was discovered on March 26, 2024, and Microsoft was notified the same day. Microsoft's security team addressed the issue and deployed a patch within 72 hours, by March 29, 2024. The swift response from Microsoft prevented widespread exploitation, but the potential impact of such a breach was significant, given that Azure Cosmos DB is a globally distributed, multi-model database service used by numerous enterprises for mission-critical applications. The service supports various data models including document, key-value, graph, and column-family, making it a versatile choice for developers.

While the vulnerability has been patched, the incident highlights ongoing security challenges in cloud-native environments. The ability for a single vulnerability to grant access to a platform-wide key underscores the importance of robust security measures and continuous monitoring. Cloud providers like Microsoft invest heavily in security, but the complexity of distributed systems and the constant evolution of attack vectors mean that vulnerabilities can still emerge. Wiz's proactive disclosure and Microsoft's rapid remediation demonstrate a collaborative approach to cloud security, aiming to protect customers from potential threats. The CosmosEscape vulnerability specifically targeted the isolation mechanisms designed to keep customer data separate and secure within the multi-tenant Azure environment.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next