CVE-2024-4879
KEVmassUnauthenticated RCE via Jelly Template Injection in ServiceNow Now Platform
CISA: ServiceNow Improper Input Validation Vulnerability
CVE-2024-4879 is an improper input validation flaw (CWE-1287) in the ServiceNow Now Platform that permits jelly template injection through UI macros. An unauthenticated attacker can submit crafted input that is improperly handled by the jelly templating engine, resulting in code execution on the instance. Successful exploitation therefore grants unauthenticated remote code execution on affected ServiceNow deployments. Organizations running Utah, Vancouver, or Washington DC Now Platform releases are affected, including the many enterprises and government agencies that expose ServiceNow portals to the internet for employee, customer, or citizen use. The flaw is confirmed exploited in the wild (added to CISA KEV on 2024-07-29), carries a maximal EPSS estimate of 100% probability of exploitation within 30 days, and has no known public PoC.
What to do: Apply the patched Now Platform builds for the Utah, Vancouver, and Washington DC release trains per ServiceNow's advisory, as required by the CISA KEV listing. Because exploitation is confirmed and requires no authentication, prioritize internet-facing instances, restrict public access where feasible until patched, and review instance logs for signs of exploitation. Confirm every release train in your environment is covered, since all three (Utah, Vancouver, Washington DC) are affected.
| ServiceNow Now Platform (Utah) | Utah releases |
| ServiceNow Now Platform (Vancouver) | Vancouver releases |
| ServiceNow Now Platform (Washington DC) | Washington DC releases |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
- Affected
- ServiceNow Utah, Vancouver, and Washington DC Now Platform
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- servicenow
- Products
- servicenow
- Weakness
- CWE-1287
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X