Home Update Microsoft nearly gave away the keys to everybody’s Azure…

Microsoft nearly gave away the keys to everybody’s Azure…

3
Top view of three 3 keys on a wooden blue table

Microsoft has had a slender escape from whole embarrassment: A safety firm uncovered a essential vulnerability that would have compromised all Azure Cosmos DB databases — each these of consumers and Microsoft’s personal.

Google subsidiary Wiz discovered a flaw within the database’s Gremlin API, normally used for storing and managing property graph information.

If dangerous actors had found it first, they might have exploited it to amass what Wiz known as the Cosmos Master Key, which might have enabled them to make use of the first key of any Cosmos database, leading to learn and write entry to any account. They would even have had entry to an inventory of each database on the service, with identifiers reminiscent of subscription and tenant IDs.



Source hyperlink

LEAVE A REPLY

Please enter your comment!
Please enter your name here