July 29, 2024 · Applied Cybernetics Group
CVE-2024-4879 — ServiceNow Utah, Vancouver, and Washington DC Now Platform
ServiceNow Improper Input Validation Vulnerability
- Added to KEV
2024-07-29- Federal due date
2024-08-19- Vendor
- ServiceNow
- Product
- Utah, Vancouver, and Washington DC Now Platform
- EPSS
- 100.0th percentile (score 0.943, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2024-4879
CISA short description
ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.