Wiz Research disclosed Wednesday that a chain of vulnerabilities in Azure Cosmos DB's Gremlin query engine — which the firm named CosmosEscape — allowed any attacker with a standard Cosmos DB account ...
A critical Gremlin API vulnerability exposed a path to any Cosmos DB instance, including Microsoft’s own services, before the company redesigned the platform. A critical vulnerability in Microsoft ...
Wiz Research has disclosed CosmosEscape, a vulnerability chain in Azure Cosmos DB that yielded read and write access to every database on the service. Microsoft has completed remediation, and no ...
Microsoft has had a narrow escape from total embarrassment: A security company uncovered a critical vulnerability that could have compromised all Azure Cosmos DB databases — both those of customers ...