HomeSecuritySecurity Explorations Reveals Vulnerabilities in Google App Engine

Security Explorations Reveals Vulnerabilities in Google App Engine

Security Explorations, a Poland-based security firm, on May 15th disclosed technical details and Proof of Concept (PoC) codes for unconfirmed and unpatched vulnerabilities in Google App Engine for Java.

In October 2012, the company began research into Google App Engine for Java, but was unable to continue. Then, in October 2014, it resumed the project.

Security Explorations Reveals Vulnerabilities in Google App Engine
The company confirmed more than 30 vulnerabilities in December.
According to a report published in SecurityWeek, it had identified and reported a total of 41 issues to the relevant authority, but Google said it had fixed those flaws internally.

 

"This is not a good sign for Google GAE engineers and their Java security skills in particular," said Adam Gowdiak, founder and CEO of Security Explorations.

To date, Google has confirmed a total of 36 vulnerabilities. However, Security Explorations confirmed that a few more have been left unpatched.

Despite this, in mid-March Security Exploration revealed 31 flaws, which were recently patched by Google, Gowdiak wrote in an email that there are still seven different vulnerabilities in Google's service, which he briefly mentioned in his message.

He said that the flaws were reported to Google three weeks ago. However, he has not received confirmation from Google officials. Nor has the relevant authority said whether it has fixed any of them.

“It’s been three weeks and we haven’t heard any official confirmation or denial from Google regarding issues 37-41,” Gowdiak wrote. “It shouldn’t take more than 1-2 business days for a major software vendor to run the received POC, read our report, and/or consult the source code.”

Security Explorations Reveals Vulnerabilities in Google App EngineHe added that the flaws are easy for attackers to exploit. They could use the freely available cloud platform to run a malicious Java application.

Hackers could use the restricted environment to attack lower-level assets and retrieve sensitive information from Google.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS