CVE-2024-4879: ServiceNow Improper Input Validation Vulnerability

Published Jul 10, 2024
·
Updated

ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.

Other sources

ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely.

CISA

Affected Software

91 affected components
ServiceNow ServiceNow=utah
ServiceNow ServiceNow=utah-early_availability
ServiceNow ServiceNow=utah-patch_1
ServiceNow ServiceNow=utah-patch_1_hotfix_1
ServiceNow ServiceNow=utah-patch_1_hotfix_1a
ServiceNow ServiceNow=utah-patch_1_hotfix_1b
ServiceNow ServiceNow=utah-patch_1_hotfix_2
ServiceNow ServiceNow=utah-patch_10
ServiceNow ServiceNow=utah-patch_10_hotfix_1
ServiceNow ServiceNow=utah-patch_10_hotfix_2
ServiceNow ServiceNow=utah-patch_10a
ServiceNow ServiceNow=utah-patch_10a_hotfix_1
ServiceNow ServiceNow=utah-patch_2
ServiceNow ServiceNow=utah-patch_2_hotfix_1
ServiceNow ServiceNow=utah-patch_2_hotfix_2
ServiceNow ServiceNow=utah-patch_2_hotfix_3
ServiceNow ServiceNow=utah-patch_2_hotfix_4
ServiceNow ServiceNow=utah-patch_3
ServiceNow ServiceNow=utah-patch_3_hotfix_1
ServiceNow ServiceNow=utah-patch_3_hotfix_1b
ServiceNow ServiceNow=utah-patch_4
ServiceNow ServiceNow=utah-patch_4_hotfix_1
ServiceNow ServiceNow=utah-patch_4_hotfix_2
ServiceNow ServiceNow=utah-patch_4_hotfix_2a
ServiceNow ServiceNow=utah-patch_4_hotfix_2b
ServiceNow ServiceNow=utah-patch_4_hotfix_3
ServiceNow ServiceNow=utah-patch_4_hotfix_3b
ServiceNow ServiceNow=utah-patch_4_hotfix_4
ServiceNow ServiceNow=utah-patch_4_hotfix_4b
ServiceNow ServiceNow=utah-patch_4_hotfix_5
ServiceNow ServiceNow=utah-patch_5
ServiceNow ServiceNow=utah-patch_5_hotfix_1
ServiceNow ServiceNow=utah-patch_6
ServiceNow ServiceNow=utah-patch_6_hotfix_1
ServiceNow ServiceNow=utah-patch_6_hotfix_2
ServiceNow ServiceNow=utah-patch_7
ServiceNow ServiceNow=utah-patch_7_hotfix_1
ServiceNow ServiceNow=utah-patch_7_hotfix_2
ServiceNow ServiceNow=utah-patch_7a
ServiceNow ServiceNow=utah-patch_7b
ServiceNow ServiceNow=utah-patch_8
ServiceNow ServiceNow=utah-patch_8_hotfix_2
ServiceNow ServiceNow=utah-patch_9
ServiceNow ServiceNow=utah-patch_9_hotfix_1
ServiceNow ServiceNow=utah-patch_9_hotfix_1a
ServiceNow ServiceNow=utah-patch_9_hotfix_1b
ServiceNow ServiceNow=vancouver
ServiceNow ServiceNow=vancouver-patch_1
ServiceNow ServiceNow=vancouver-patch_1_hotfix_1
ServiceNow ServiceNow=vancouver-patch_10
ServiceNow ServiceNow=vancouver-patch_2
ServiceNow ServiceNow=vancouver-patch_2_hotfix_1
ServiceNow ServiceNow=vancouver-patch_2_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_2_hotfix_2
ServiceNow ServiceNow=vancouver-patch_2_hotfix_3
ServiceNow ServiceNow=vancouver-patch_2_hotfix1a
ServiceNow ServiceNow=vancouver-patch_3
ServiceNow ServiceNow=vancouver-patch_3_hotfix_1
ServiceNow ServiceNow=vancouver-patch_3_hotfix_2
ServiceNow ServiceNow=vancouver-patch_3_hotfix_3
ServiceNow ServiceNow=vancouver-patch_3_hotfix_4
ServiceNow ServiceNow=vancouver-patch_4
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_4_hotfix_1b
ServiceNow ServiceNow=vancouver-patch_4_hotfix_2b
ServiceNow ServiceNow=vancouver-patch_5
ServiceNow ServiceNow=vancouver-patch_5_hotfix_1
ServiceNow ServiceNow=vancouver-patch_6
ServiceNow ServiceNow=vancouver-patch_6_hotfix_1
ServiceNow ServiceNow=vancouver-patch_7
ServiceNow ServiceNow=vancouver-patch_7_hotfix_1
ServiceNow ServiceNow=vancouver-patch_7_hotfix_1a
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2a
ServiceNow ServiceNow=vancouver-patch_7_hotfix_2b
ServiceNow ServiceNow=vancouver-patch_7_hotfix_3a
ServiceNow ServiceNow=vancouver-patch_8
ServiceNow ServiceNow=vancouver-patch_8_hotfix_1
ServiceNow ServiceNow=vancouver-patch_8_hotfix_2
ServiceNow ServiceNow=vancouver-patch_8_hotfix_3
ServiceNow ServiceNow=vancouver-patch_9
ServiceNow ServiceNow=washington_dc
ServiceNow ServiceNow=washington_dc-patch_1
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_2
ServiceNow ServiceNow=washington_dc-patch_1_hotfix_2a
ServiceNow ServiceNow=washington_dc-patch_2
ServiceNow ServiceNow=washington_dc-patch_2_hotfix_1
ServiceNow ServiceNow=washington_dc-patch_3
ServiceNow Utah, Vancouver, and Washington DC Now Platform

Event History

Jul 10, 2024
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 25, 2024
News Published
via BleepingComputer·08:58 PM
News Published
via BleepingComputer·09:00 PM
Jul 29, 2024
Known Exploited
via CISA·12:00 AM
News Published
via Dark Reading·08:46 PM
Dec 20, 2024
News Published
via Dark Reading·12:00 AM
May 26, 2025
News Published
via The Register·04:28 AM
News Published
via The Register·04:32 AM
Aug 11, 2025
Exploit Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-4879?

CVE-2024-4879 is classified as a critical vulnerability that allows remote code execution.

2

How do I fix CVE-2024-4879?

To fix CVE-2024-4879, users should apply the latest security patch provided by ServiceNow for the affected versions.

3

Which versions of ServiceNow are affected by CVE-2024-4879?

CVE-2024-4879 affects ServiceNow releases Utah, Vancouver, and Washington DC.

4

Can CVE-2024-4879 be exploited by unauthenticated users?

Yes, CVE-2024-4879 can be exploited remotely by unauthenticated users, allowing them to execute code.

5

What impact does CVE-2024-4879 have on the Now Platform?

CVE-2024-4879 could enable harmful actions within the Now Platform, potentially leading to data breaches.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203