Back to Labs
Security Advisory

CVE-2024-4879

About

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

Weakness (CWE):CWE-1287

Rainforest analyst review

ServiceNow's Now Platform, in the Vancouver and Washington DC releases, has an input-validation flaw in how it handles Jelly template expressions in incoming requests. Because user-supplied input is evaluated by the server-side template engine rather than treated as data, an unauthenticated attacker can craft a request that injects a template expression the platform executes, resulting in remote code execution within the context of the Now Platform instance.

ServiceNow is a central system of record for IT service management, workflows, and often sensitive operational and employee data across large enterprises and government, so code execution on an instance exposes a broad and valuable data set. The flaw was chained with other ServiceNow issues in publicly documented exploit chains, and mass scanning for vulnerable instances followed disclosure, with reports of data exfiltration from unpatched deployments. Apply the ServiceNow patches and hot fixes for your release immediately; hosted instances were updated by ServiceNow, but self-hosted and partner-managed instances must be verified, and because scanning began quickly, review exposed instances for signs of data access and unauthorized queries.

References

Related CVEs

No related CVEs.

Frequently asked questions

What is CVE-2024-4879?

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers.

How severe is CVE-2024-4879?

CVE-2024-4879 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.

How is CVE-2024-4879 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2024-4879?

Public advisories list the following as affected: servicenow. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2024-4879?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email