Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will no longer support Rhino as the JavaScript execution engine. No further fix actions are needed.
Metrics
Affected Vendors & Products
References
History
Thu, 06 Feb 2025 11:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will no longer support Rhino as the JavaScript execution engine. No further fix actions are needed. | |
Title | Sandbox Escape in Google Cloud Application Integration's JavaScript Task (Rhino Engine) | |
Weaknesses | CWE-829 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Google
Published: 2025-02-06T11:37:57.460Z
Updated: 2025-02-12T19:51:10.116Z
Reserved: 2025-02-03T10:57:57.923Z
Link: CVE-2025-0982

No data.

Status : Received
Published: 2025-02-06T12:15:27.267
Modified: 2025-02-06T12:15:27.267
Link: CVE-2025-0982

No data.