This week’s highlights include a new JinJava rule targeting a sandbox-bypass flaw that could allow malicious template input to escape execution controls. The rule improves detection for unsafe template rendering paths.
Key Findings
New WAF rule deployed for JinJava (CVE-2025-59340) to block a sandbox bypass in the template engine that permits attacker-controlled type construction and arbitrary class instantiation; in vulnerable environments this can escalate to remote code execution and full server compromise.
Impact
- CVE-2025-59340 — Exploitation enables attacker-supplied type descriptors / Jackson
ObjectMapperabuse, allowing arbitrary class loading, file/URL access (LFI/SSRF primitives) and, with suitable gadget chains, potential remote code execution and system compromise.
| Ruleset | Rule ID | Legacy Rule ID | Description | Previous Action | New Action | Comments |
|---|---|---|---|---|---|---|
| Cloudflare Managed Ruleset | b327d6442e2d4848b4aab3cbc04bab5f | 100892 | JinJava – SSTI – CVE:CVE-2025-59340 | Log | Block | This is a New Detection |
Source: Cloudflare
Latest Posts
- Microsoft Teams: Join by code requires owner approval for private teams [MC1183610]
![Microsoft Teams: Join by code requires owner approval for private teams [MC1183610] 2 pexels pixabay 461169](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Rate my call feedback experience update in Microsoft Teams [MC1183608]
![Rate my call feedback experience update in Microsoft Teams [MC1183608] 3 pexels rostislav 5011647](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Consult and merge into a meeting or group call via Dual-Tone Multi-Frequency (DTMF) [MC1183611]
![Consult and merge into a meeting or group call via Dual-Tone Multi-Frequency (DTMF) [MC1183611] 4 pexels ben neale 123878 380337](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Power Apps – Deprecation of Maker Copilot in canvas apps [MC1183604]
![Power Apps – Deprecation of Maker Copilot in canvas apps [MC1183604] 5 pexels googledeepmind 17483871](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Microsoft Teams: Join by code requires owner approval for private teams [MC1183610] 2 pexels pixabay 461169](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-461169-150x150.webp)
![Rate my call feedback experience update in Microsoft Teams [MC1183608] 3 pexels rostislav 5011647](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-rostislav-5011647-150x150.webp)
![Consult and merge into a meeting or group call via Dual-Tone Multi-Frequency (DTMF) [MC1183611] 4 pexels ben neale 123878 380337](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-ben-neale-123878-380337-150x150.webp)
![Power Apps – Deprecation of Maker Copilot in canvas apps [MC1183604] 5 pexels googledeepmind 17483871](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-googledeepmind-17483871-150x150.webp)
![Retiring the “Refresh all on page” button in OneNote Meeting Details pane by end of 2025 [MC1171847] 7 Retiring the “Refresh all on page” button in OneNote Meeting Details pane by end of 2025 [MC1171847]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-skylar-kang-6046814-150x150.webp)