ChaosDB (Aug 2021): A Cosmos DB Flaw Exposed Thousands of Azure Customers' Keys
Retrospective: this article looks back at events from August 2021, written in 2026 with the benefit of hindsight.
In August 2021, researchers at Wiz disclosed ChaosDB, a vulnerability in Microsoft Azure Cosmos DB that could have allowed an attacker to obtain the primary access keys of other customers' databases.
How it worked
Cosmos DB had added a Jupyter Notebook feature for data visualization. Wiz found that a series of misconfigurations in the notebook feature allowed escalation from a notebook container to access other customers' notebooks and, critically, credentials that could retrieve their Cosmos DB primary keys. Primary keys grant full read, write and delete access to a database. The notebook feature had been automatically enabled for a large number of accounts.
Microsoft's response
Microsoft disabled the vulnerable feature within days of the report and notified thousands of potentially affected customers, advising them to regenerate their primary keys. Microsoft said it found no evidence of exploitation by anyone other than the researchers. Wiz received a bug bounty.
Why it mattered
ChaosDB was one of the first major public demonstrations of a cross-tenant vulnerability in a cloud provider's managed service — a flaw in the provider's layer, not the customer's configuration. Customers could do nothing to prevent it, but they could limit the impact.
Lessons in hindsight
- Key-based access is fragile. Cosmos DB supports Entra ID role-based access for data plane operations; using it and disabling key-based authentication removes the most damaging outcome.
- Rotate keys when told. Many customers took weeks to rotate.
- Be skeptical of features enabled by default. Review new service features for exposure.
- Monitor data plane access with diagnostic logs.
In hindsight
Wiz and other researchers found several more cross-tenant cloud vulnerabilities in following years, including OMIGOD. Providers expanded bug bounties and isolation reviews, but the lesson for customers stayed constant: prefer identity-based access over shared keys wherever possible.
- How to Rotate Cosmos DB Keys and Move to Entra ID Authentication How-To & Hardening
- Detecting Cosmos DB Key Misuse With Defender for Cloud and Sentinel Detection & Response
- CIO Brief: When the Cloud Provider's Own Service Is Vulnerable CIO Briefings