LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-4879: ServiceNow Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 29, 2024
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 19, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-4879 to its Known Exploited Vulnerabilities catalog on Jul 29, 2024, with a federal patch deadline of Aug 19, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute…

CVE-2024-4879 is an improper input validation vulnerability in certain ServiceNow Now Platform releases that enables jelly template injection in UI macros. An unauthenticated attacker can exploit it to achieve remote code execution. This matters because ServiceNow platforms often hold sensitive operational and business data; successful exploitation could allow full system compromise without credentials, putting connected environments at risk of further intrusion or data theft.

Defenders should treat this as a high-priority remote code execution issue in a widely deployed enterprise platform and confirm all details against the vendor advisory before acting.

How it works

The vulnerability is classified under CWE-1287 and stems from improper input validation that permits jelly template injection within UI macros on the ServiceNow Now Platform. Jelly is a templating mechanism used in ServiceNow interfaces. When input is not properly validated, an attacker can supply crafted content that the platform interprets and executes as template code.

According to the CISA summary, an unauthenticated user can exploit this to execute code remotely. The attack surface is the UI macro handling path; no authentication is required. Exact injection payloads or request formats are not detailed in the available facts and must be confirmed against the vendor advisory. In general for this class of flaw, the attacker abuses the lack of sanitization to inject template directives that the server evaluates with elevated privileges, leading to arbitrary code execution on the underlying system.

Am I affected? How to find it in your systems

The vulnerability affects ServiceNow Utah, Vancouver, and Washington DC Now Platform releases. ServiceNow instances typically run as cloud-hosted or on-premises enterprise platforms used for IT service management, workflow automation, and related business processes. Inventory all ServiceNow deployments in your environment by reviewing asset management records, cloud console inventories, and network scans for ServiceNow-related hostnames or IP ranges.

Public detail on precise version ranges or telemetry signatures is limited; always validate findings against the official vendor advisory.

How to remediate

The primary remediation is to apply the mitigations or updates provided by ServiceNow for the Utah, Vancouver, and Washington DC Now Platform releases. Follow the vendor instructions exactly. CISA requires applying mitigations per vendor instructions or discontinuing use of the product if mitigations are unavailable.

Document the change window and verify that no residual vulnerable components remain.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls focused on the unauthenticated remote code execution path.

These measures lower risk but do not eliminate it; prioritize full remediation.

If your data may have been exposed

Actively exploited remote code execution vulnerabilities of this type can lead to full platform compromise and subsequent data breaches. If you suspect exploitation, isolate the affected ServiceNow instance, preserve logs, and begin incident response. Known ransomware use is not documented for this CVE. As a general precaution, individuals whose credentials or personal data may have been involved can run a free exposure scan of their email addresses against known breach data sets to check for prior compromise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedServiceNow · Utah, Vancouver, and Washington DC Now Platform
WeaknessCWE-1287
Added to CISA KEVJul 29, 2024
Federal patch deadlineAug 19, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities