As cited
Copy frozen at (site build).
cloud saas
ChaosDB: How to discover your vulnerable Azure Cosmos DBs and protect them
Wiz Research discovered a critical vulnerability in Azure Cosmos DB that allows any Azure user to gain full administrative access to other customers' Cosmos DB instances without authorization. The flaw enables attackers to read, write, and delete data across affected databases. The vulnerability represents a severe tenant isolation failure affecting the multi-tenant service.
Why it matters: Organizations using Azure Cosmos DB face immediate data exposure and loss risks; practitioners should urgently audit their Cosmos DB configurations and contact Microsoft for remediation guidance.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
cloud saas
ChaosDB: How to discover your vulnerable Azure Cosmos DBs and protect them
Wiz Research discovered a critical vulnerability in Azure Cosmos DB that allows any Azure user to gain full administrative access to other customers' Cosmos DB instances without authorization. The flaw enables attackers to read, write, and delete data across affected databases. The vulnerability represents a severe tenant isolation failure affecting the multi-tenant service.
Why it matters: Organizations using Azure Cosmos DB face immediate data exposure and loss risks; practitioners should urgently audit their Cosmos DB configurations and contact Microsoft for remediation guidance.
- Source published
- First seen by Cybersecurity Tracker