Back to Labs
Security Advisory

CVE-2024-5217

About

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

Weakness (CWE):CWE-184CWE-697

Rainforest analyst review

ServiceNow's Now Platform contained an input-validation flaw in its Glide expression handling that allowed an unauthenticated attacker to remotely execute code within the platform's context. The defect stems from incomplete validation and incorrect comparison logic when processing certain template expressions, which an attacker can abuse to break out of the intended evaluation and run code on the instance. No credentials are required, and it is one of a chained set of Now Platform issues from the same patch cycle that together enabled data theft and full instance compromise.

ServiceNow instances are workflow and IT-service-management hubs that concentrate enormous amounts of sensitive organizational data, from employee records to internal tickets and integration credentials, and they are typically internet-accessible for staff and partners. Researchers demonstrated that the chained flaws could dump entire databases from unauthenticated instances, and mass scanning and exploitation attempts followed disclosure quickly. Apply the June 2024 patches and hot fixes for the Washington DC, Vancouver, and earlier releases as an urgent priority, and because working exploit chains circulated publicly, review instances for unauthorized data access and anomalous queries rather than treating the update as the end of the response.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2024-5217?

ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. The vulnerability is addressed in the listed patches and hot fixes below, which were released during the June 2024 patching cycle.

How severe is CVE-2024-5217?

CVE-2024-5217 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2024-5217 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2024-5217?

Public advisories list the following as affected: servicenow. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2024-5217?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email