services / Azure / Mongo Cluster
An Azure Cosmos DB for MongoDB (vCore) Mongo Cluster — a managed, production MongoDB-compatible database cluster resource and its control-plane configuration (SKU, node topology, networking, settings).
A production data store supporting a single organizational function; its data plane holds organizational data and its connection strings are credentials.
Microsoft.DocumentDB/mongoClusters/listConnectionStrings/action
Returns connection strings embedding cluster credentials; an attacker redeems them for direct authenticated access to read and exfiltrate all database contents, mirroring the listKeys precedent.
Risks
Scope: CRITICAL
This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.
Links
Contributed by P0 Security