Researchers from Security Explorations report that they have found several serious vulnerabilities in the Java environment in Google App Engine, part of Google's Cloud platform.
Google App Engine is a Platform as a Service (PaaS) service that is offered to run custom programs and applications using several programming languages. Many of them are written in the Java environment.
Security Explorations reports that the vulnerabilities allow an attacker to bypass the Java security sandbox and execute arbitrary scripts. In total, the researchers believe the number of issues is over 30. However, they were unable to complete their investigation because Google stopped their testing, suspending their Google App Engine account.
They hope, however, that Google will allow them to complete their research, as is also consistent with the company's sympathy and general support for the security research community.

