Skip to content
COOEY

EXPOSURES › CVE-2024-4879

CVE-2024-4879

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-07-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-4879 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 exploited-in-wildransomwaresupply-chainrceunpatched

ServiceNow's Utah, Vancouver, and Washington DC Now Platform platforms allow unauthenticated remote code execution via jelly template injection in UI macros.

This vulnerability enables unauthenticated attackers to execute arbitrary code remotely, posing a severe risk to DIB organizations relying on ServiceNow for critical infrastructure management. The active exploitation status and remote code execution capability make this a high-priority compliance failure for FedRAMP and NIST 800-171 environments. DIB orgs must immediately patch affected platforms and audit all UI macro configurations to prevent unauthorized access.

Shame score — Active exploitation of a remote code execution vulnerability in a widely deployed platform demonstrates negligent security controls and creates significant reputational damage.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.

AFFECTED FEDRAMP PRODUCTS · 1
PRODUCTSTATUS
Government Community Cloud
ServiceNow
Authorized