Back to News
Advertisement
Advertisement

⚡ Community Insights

Discussion Sentiment

50% Positive

Analyzed from 147 words in the discussion.

Trending Topics

#cosmos#vulnerability#access#admin#every#key#similar#ago#something#https

Discussion (7 Comments)Read Original on HackerNews

sakisvabout 1 hour ago
Is it me or was there a similar vulnerability reported a few years ago? Something about the attacker getting access to all platform's users' databases, though not sure if it was cosmos or something similar.
ultra2d36 minutes ago
This one from a year ago?

https://dirkjanm.io/obtaining-global-admin-in-every-entra-id...

"This vulnerability could have allowed me to compromise every Entra ID tenant in the world (except probably those in national cloud deployments)."

troelsSteeginabout 2 hours ago
"Cosmos Master Key"... I can see why that would have been convenient, but talk about a footgun. Right out of a Marvel movie. Still, if admin backdoor access is business-necessary, is the answer a unique admin access key per account?
a012about 2 hours ago
This is not the first time M$ “lost” their master key, it’s their tradition now
lateral_cloudabout 2 hours ago
It took them 6 months to fix this properly?
uvuvabout 3 hours ago
A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.
redwoodabout 2 hours ago
Incredible that this is the second time Wiz has discovered a global Cosmos DB vulnerability (https://chaosdb.wiz.io/) and a shock that anyone is trusting Microsoft, Azure or in particular Cosmos DB with anything mission critical