← All CVEs & advisories

ServiceNow CVE-2024-4879

Jelly Template Injection (SSTI) in UI Macros

RCECVSS 4.0 9.3Priority 97CISA KEVDisclosed 2024-07-10Verified

Risk & exploitation

PriorityCritical · 97/100
EPSS0.943 · 100.0th pct
CISA KEVYes — known exploited
Public exploitYes — cisa-kev, exploit-db, nuclei

EPSS (FIRST) estimates a very high likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.

Summary

Unauthenticated server-side template injection in ServiceNow UI macros that, chained with

CVE-2024-5217 / CVE-2024-5178, yields remote code execution and full database access. Added to the

CISA KEV catalog on 2024-07-29 (remediation due 2024-08-19) as an actively-exploited input-validation

flaw. Full technical detail, attack scenario, and regulatory mapping live in the cross-linked KB

article CVE-001 — this signature carries only the version matrix and the exposure-window detection

overlay.

Affected releases & fixed-in

ReleaseFixed in
Washington DCPatch 1 Hot Fix 2b / Patch 2 Hot Fix 2 / Patch 3 Hot Fix 1 / Patch 4
VancouverPatch 6 Hot Fix 2 / Patch 7 Hot Fix 3b / Patch 8 Hot Fix 4 / Patch 9 / Patch 10
UtahPatch 10 Hot Fix 3 / Patch 10a Hot Fix 2
Source & attribution

Per-release fixed-in from the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[].lessThan boundaries (versionType: custom), https://cveawg.mitre.org/api/cve/CVE-2024-4879, retrieved 2026-06-08. The same patch matrix is in login-gated KB1645154/KB1644293; the public CVE Record is the citable source. Corroborated by NVD CPE enumeration + CISA KEV.

Regulatory mapping

Decision support, not a reporting determination.

Check your instance for CVE-2024-4879

References

Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.