Security0 views

CosmosEscape: Critical Azure Cosmos DB Vulnerability Allowed Unauthorized Database Access

A severe vulnerability in Azure Cosmos DB, named CosmosEscape, enabled attackers to escape the Gremlin query sandbox and gain full read-and-write access to any customer database. The flaw allowed an attacker to craft a malicious query within a database under their control, use it to locate other customer databases, and retrieve their access keys.

Microsoft has already mitigated the issue and reports finding no unauthorized activity outside of controlled researcher testing. The company also found no evidence of actual access to customer data. Users do not need to take any action in response to this vulnerability.