Wiz가 Azure Cosmos DB의 취약점을 공개하며 책임 소재에 대한 논의가 이어졌다.
Wiz Research는 Azure Cosmos DB의 Gremlin 샌드박스를 탈출한 CosmosEscape 취약점을 공개했다. 이로 인해 전체 플랫폼의 키에 접근할 수 있는 보안 문제가 발생했으며, Microsoft는 이 문제를 두 날 만에 차단했지만, 키를 제거하는 데는 2026년 7월까지 걸렸다. 전문가들은 이러한 사건에 대한 책임 소재와 재구성에 따른 비용에 대해 논의하고 있다.
Wiz disclosed a vulnerability in Azure Cosmos DB, sparking debates on accountability and costs.
Wiz Research disclosed CosmosEscape, a vulnerability that escaped Azure Cosmos DB's Gremlin sandbox, allowing access to a key that granted read and write permissions across the platform. Microsoft blocked the entry point within two days but took until July 2026 to fully remove the key. Practitioners are debating the shared responsibility and the costs associated with the rearchitecture needed to address the issue.