Web Hack List

Collected research

Unveiling Rhino’s Blind Spot: Exploiting Custom Code Execution in Apigee

Apigee runs customer Java and JavaScript policies side by side. Naming a custom Java class in a package the Rhino class shutter allowlists, and handing an instance of it to a JavaScript policy through a flow variable, lets the script call a method that runs OS commands, escaping both the Java Security Manager and the Rhino sandbox.

Record

Published by
CodeSent
Date
Topic
Other

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of CodeSent, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .