6 comments

  • gtowey 1 hour ago
    > Cosmos DB's engine translated Gremlin queries into .NET code, enforcing a set of restrictions designed to prevent queries from reaching beyond Gremlin operations. These restrictions, however, didn't sufficiently account for .NET reflection

    Wow, this is so unbelievably amateurish.

  • troelsSteegin 3 hours ago
    "Cosmos Master Key"... I can see why that would have been convenient, but talk about a footgun. Right out of a Marvel movie. Still, if admin backdoor access is business-necessary, is the answer a unique admin access key per account?
    • a012 3 hours ago
      This is not the first time M$ “lost” their master key, it’s their tradition now
  • lateral_cloud 3 hours ago
    It took them 6 months to fix this properly?
    • delfinom 30 minutes ago
      They patched the vulnerability within 2 days. They spent 6 months rearchitecting their backend. It's a major service for themselves and tens of thousands of customers, you don't vibe code yourself a new database query execution engine overnight.
    • jasonvorhe 1 hour ago
      It's Microsoft, of course. Their org chart basically dictates it.
  • sakisv 3 hours ago
    Is it me or was there a similar vulnerability reported a few years ago? Something about the attacker getting access to all platform's users' databases, though not sure if it was cosmos or something similar.
  • redwood 3 hours ago
    Incredible that this is the second time Wiz has discovered a global Cosmos DB vulnerability (https://chaosdb.wiz.io/) and a shock that anyone is trusting Microsoft, Azure or in particular Cosmos DB with anything mission critical
  • uvuv 5 hours ago
    A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.