Microsoft patched a critical flaw in Azure Cosmos DB called CosmosEscape that allowed attackers to escape the Gremlin query sandbox and gain full read/write access to any database across customer tenants using a platform-wide key. The vulnerability affected the entire Cosmos DB platform.
Security researcher Wiz disclosed CosmosEscape, a vulnerability enabling attackers to take over databases in Microsoft's Azure Cosmos DB service. The finding was shared across tech security communities including Hacker News.