CVE ID
CVE-2024-4879
Vulnerability Name
ServiceNow Improper Input Validation Vulnerability
- Project: ServiceNow
- Product: Utah, Vancouver, and Washington DC Now Platform
Date
- Date Added: 2024-07-29
- Due Date: 2024-08-19
Description
ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.
Known To Be Used in Ransomware Campaigns?
Unknown
Action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1645154; https://nvd.nist.gov/vuln/detail/CVE-2024-4879
Related Security News
- ServiceNow warns of three max severity security vulnerabilities
- Critical ServiceNow RCE flaws actively exploited to steal credentials
- Researchers Reveal ConfusedFunction Vulnerability in Google Cloud Platform


