CVE-2024-4879

ServiceNow Utah, Vancouver, and Washington DC Now Platform: Improper Input Validation

As of , CVE-2024-4879 in ServiceNow Utah, Vancouver, and Washington DC Now Platform is on CISA's list of exploited vulnerabilities: CISA listed it on . Our patch-first group: Patch this week.

Exploited
Yes: CISA listed it on 29 July 2024
US federal deadline
19 August 202421 days after CISA listed it. US federal civilian agencies must fix it by then.
Used in ransomware campaigns
Not known to CISA
EPSS score
0.99Higher than 99% of the CVEs EPSS scores. EPSS estimates the chance of exploitation activity in the next 30 days.
EPSS when listed
0.01 on 29 July 2024EPSS on the day CISA listed it.
Public exploit
1 Exploit-DB entry
Fix
Vendor advice: support.servicenow.comLinks below, from CISA's entry.

What CISA says to do

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA's required action

What the flaw is

ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.

CISA's description

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

The CVE record's description, from SN

CVE published
10 July 2024
Assigned by
SN
CVSS
9.3 Critical (CVSS 4.0, from the CNA)
CWE-1287
Improper Validation of Specified Type of Input
CISA SSVC, exploitation
active
CISA SSVC, automatable
yes
CISA SSVC, technical impact
total

Timeline

  1. The CVE record was published.
  2. CISA added it to its list of exploited vulnerabilities.
  3. The US federal deadline to fix it.
  4. CISA changed its entry. Renamed from Utah, Vancouver, and Washington DC Now to Utah, Vancouver, and Washington DC Now Platform. Edited: description.
  5. Exploit-DB published an exploit (EDB-ID 52410).

Public exploits

Facts from Metasploit's module list and Exploit-DB's index; we never copy exploit code.

Utah, Vancouver, and Washington DC Now Platform: other exploited entries

VulnerabilityProductOur groupListedDeadlineEPSS
CVE-2024-5217Incomplete List of Disallowed InputsServiceNow Utah, Vancouver, and Washington DC Now PlatformPatch this weekEPSS 0.990.99

Read further