Adam Gowdiak Discloses Unpatched Security Flaws in Google App Engine
Google’s Project Zero vulnerability research group has drawn some flak recently for its practice of publicly disclosing security flaws in software from other vendors after a 90-day notice period, regardless of whether patches are available or not.
Friday, the company may have gotten a small taste of its own medicine when Polish firm Security Explorations Friday released details on several unpatched vulnerabilities in Google’s cloud software after the Internet giant allegedly failed to respond in a timely manner to the issue.
The vulnerabilities in Google’s App Engine (GAE) software include three complete Java sandbox escapes that could be used to gather a lot of information on the Java Runtime Environment sandbox itself. “They also seem to be a potentially good starting point to proceed with attacks against the OS sandbox and RPC services visible to the sandboxed Java environment,” Adam Gowdiak, CEO of Security Explorations said in emailed comments to Dark Reading.