EXPOSURES › CVE-2024-4879
CVE-2024-4879
HIGH ⌖ ON CISA KEV · EXPLOITEDServiceNow's Utah, Vancouver, and Washington DC Now Platform platforms allow unauthenticated remote code execution via jelly template injection in UI macros.
This vulnerability enables unauthenticated attackers to execute arbitrary code remotely, posing a severe risk to DIB organizations relying on ServiceNow for critical infrastructure management. The active exploitation status and remote code execution capability make this a high-priority compliance failure for FedRAMP and NIST 800-171 environments. DIB orgs must immediately patch affected platforms and audit all UI macro configurations to prevent unauthorized access.
Shame score — Active exploitation of a remote code execution vulnerability in a widely deployed platform demonstrates negligent security controls and creates significant reputational damage.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.
| PRODUCT | STATUS |
|---|---|
| Government Community Cloud ServiceNow |
Authorized |