ZeroHour

CVE-2024-4879

KEVmass

Unauthenticated RCE via Jelly Template Injection in ServiceNow Now Platform

CISA: ServiceNow Improper Input Validation Vulnerability

CVSS 4.0
9.3 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2024-4879 is an improper input validation flaw (CWE-1287) in the ServiceNow Now Platform that permits jelly template injection through UI macros. An unauthenticated attacker can submit crafted input that is improperly handled by the jelly templating engine, resulting in code execution on the instance. Successful exploitation therefore grants unauthenticated remote code execution on affected ServiceNow deployments. Organizations running Utah, Vancouver, or Washington DC Now Platform releases are affected, including the many enterprises and government agencies that expose ServiceNow portals to the internet for employee, customer, or citizen use. The flaw is confirmed exploited in the wild (added to CISA KEV on 2024-07-29), carries a maximal EPSS estimate of 100% probability of exploitation within 30 days, and has no known public PoC.

What to do: Apply the patched Now Platform builds for the Utah, Vancouver, and Washington DC release trains per ServiceNow's advisory, as required by the CISA KEV listing. Because exploitation is confirmed and requires no authentication, prioritize internet-facing instances, restrict public access where feasible until patched, and review instance logs for signs of exploitation. Confirm every release train in your environment is covered, since all three (Utah, Vancouver, Washington DC) are affected.

Affected
ServiceNow Now Platform (Utah)Utah releases
ServiceNow Now Platform (Vancouver)Vancouver releases
ServiceNow Now Platform (Washington DC)Washington DC releases
Estimated exposure
masslikely millions of enterprise users across tens of thousands of deployed Now Platform instances, many of them internet-exposed (order-of-magnitude estimate;… — ServiceNow is the dominant enterprise workflow/ITSM SaaS platform, deployed by thousands of large organizations whose employee and customer user bases run to millions, and public internet scans routinely surface tens of thousands of Now…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

CISA Known Exploited Vulnerability
Affected
ServiceNow Utah, Vancouver, and Washington DC Now Platform
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
servicenow
Products
servicenow
Weakness
CWE-1287
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news