Security News > 2022 > November > Microsoft fixes critical RCE flaw affecting Azure Cosmos DB

Analysts at Orca Security have found a critical vulnerability affecting Azure Cosmos DB that allowed unauthenticated read and write access to containers.
Named CosMiss, the security issue is in Azure Cosmos DB built-in Jupyter Notebooks that integrate into the Azure portal and Azure Cosmos DB accounts for querying, analyzing, and visualizing NoSQL data and results easier.
Azure Cosmos DB is Microsoft's fully managed NoSQL database that features broad API type support for applications of all sizes.
Jupyter Notebooks is a web-based interactive platform that allows users to access Cosmos DB data.
When a user creates a new Notebook on Azure Cosmos DB, a new endpoint is created along with a unique new session/notebook ID. The researchers reviewed the traffic of the request from a newly created notebook to the server and noticed the existence of an Authorization Header.
Since Azure Cosmos DB is a fully managed, serverless distributed database, the fixes are taking place on the server side, so users don't need to take any action to mitigate the risk.
News URL
Related news
- Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score (source)
- Critical RCE bug in Microsoft Outlook now exploited in attacks (source)
- Microsoft Sues Hacking Group Exploiting Azure AI for Harmful Content Creation (source)
- Azure, Microsoft 365 MFA outage locks out users across regions (source)
- Hackers exploit critical Aviatrix Controller RCE flaw in attacks (source)
- Critical SimpleHelp Flaws Allow File Theft, Privilege Escalation, and RCE Attacks (source)
- Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation (source)
- Hackers exploit Cityworks RCE bug to breach Microsoft IIS servers (source)
- Microsoft names alleged credential-snatching 'Azure Abuse Enterprise' operators (source)
- Microsoft Exposes LLMjacking Cybercriminals Behind Azure AI Abuse Scheme (source)