Hacker News new | ask | show | jobs
by sakisv 2 days ago
Is it me or was there a similar vulnerability reported a few years ago? Something about the attacker getting access to all platform's users' databases, though not sure if it was cosmos or something similar.
3 comments

This one from a year ago?

https://dirkjanm.io/obtaining-global-admin-in-every-entra-id...

"This vulnerability could have allowed me to compromise every Entra ID tenant in the world (except probably those in national cloud deployments)."

oh ffs, I forgot about this. I was thinking of the other one though from 2021 mentioned in a sibling comment, and it was indeed, again, with cosmos
There have been a lot. I remember one that was essentially “send the request without an Authorization header.”