Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
Posted by PrivacyWire
Cybersecurity researchers at Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.