Hacker News new | ask | show | jobs
Azure's Weakest Link – Full Cross-Tenant Compromise (binarysecurity.no)
1 points by hland 295 days ago
1 comments

API Connections allow anyone to fully compromise any other Connection worldwide, giving full access to the connected Backend. This includes cross-tenant compromise of Key Vaults and Azure SQL databases, as well as any other externally connected service, such as Jira or SalesForce.