First published: Thu Feb 06 2025(Updated: )
Sandbox escape in the JavaScript Task feature of Google Cloud Application Integration allows an actor to execute arbitrary unsandboxed code via crafted JavaScript code executed by the Rhino engine. Effective January 24, 2025, Application Integration will no longer support Rhino as the JavaScript execution engine. No further fix actions are needed.
Credit: cve-coordination@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Google Cloud Application Integration |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-0982 is classified as high due to its potential for allowing arbitrary unsandboxed code execution.
To fix CVE-2025-0982, upgrade to the latest version of Google Cloud Application Integration that no longer supports the Rhino engine.
The potential impacts of CVE-2025-0982 include unauthorized execution of code, data breaches, and possible disruption of services.
Yes, Google has announced that support for Rhino will end on January 24, 2025, as a mitigation for CVE-2025-0982.
Users of Google Cloud Application Integration that utilize the JavaScript Task feature are affected by CVE-2025-0982.