Security News > 2022 > November > Microsoft fixes critical RCE flaw affecting Azure Cosmos DB
Analysts at Orca Security have found a critical vulnerability affecting Azure Cosmos DB that allowed unauthenticated read and write access to containers.
Named CosMiss, the security issue is in Azure Cosmos DB built-in Jupyter Notebooks that integrate into the Azure portal and Azure Cosmos DB accounts for querying, analyzing, and visualizing NoSQL data and results easier.
Azure Cosmos DB is Microsoft's fully managed NoSQL database that features broad API type support for applications of all sizes.
Jupyter Notebooks is a web-based interactive platform that allows users to access Cosmos DB data.
When a user creates a new Notebook on Azure Cosmos DB, a new endpoint is created along with a unique new session/notebook ID. The researchers reviewed the traffic of the request from a newly created notebook to the server and noticed the existence of an Authorization Header.
Since Azure Cosmos DB is a fully managed, serverless distributed database, the fixes are taking place on the server side, so users don't need to take any action to mitigate the risk.
News URL
Related news
- Microsoft warns Azure Virtual Desktop users of black screen issues (source)
- Microsoft SharePoint RCE bug exploited to breach corporate network (source)
- Synology Urges Patch for Critical Zero-Click RCE Flaw Affecting Millions of NAS Devices (source)
- HPE warns of critical RCE flaws in Aruba Networking access points (source)
- Critical Veeam RCE bug now used in Frag ransomware attacks (source)
- Palo Alto Networks warns of critical RCE zero-day exploited in attacks (source)
- Critical RCE bug in VMware vCenter Server now exploited in attacks (source)
- Critical 9.8-rated VMware vCenter RCE bug exploited after patch fumble (source)
- Veeam warns of critical RCE bug in Service Provider Console (source)
- Exploit released for critical WhatsUp Gold RCE flaw, patch now (source)