Junglewise Threat Intelligence

CVE-2024-5217: ServiceNow Incomplete List of Disallowed Inputs Vulnerability

CVE-2024-5217 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-07-29

Vendors: ServiceNow.

Executive brief

ServiceNow Now Platform contains an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated remote attacker can exploit this to execute arbitrary code within the context of the platform.

Affected products

  • ServiceNow Now Platform Washington DC Prior to June 2024 patches
  • ServiceNow Now Platform Vancouver Prior to June 2024 patches
  • ServiceNow Now Platform Utah Prior to June 2024 patches

Timeline

  • 2024-06: patched: Patches and hotfixes released during the June 2024 patching cycle.
  • 2024-07-29: disclosed
  • 2024-07-29: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2024-07-29: exploited: Reported as actively exploited in the wild.

Related threats