cve entity

CVE-2024-4879

1 source-linked records in the current knowledge graph.

high

CVE-2024-4879: ServiceNow Improper Input Validation Vulnerability

ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute code remotely. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-4879EPSS 100.0%ServiceNowUtah, Vancouver, and Washington DC Now Platform
CISA KEV ↗ · unattributed attribution