ServiceNow CVE-2024-4879
Jelly Template Injection (SSTI) in UI Macros
Risk & exploitation
EPSS (FIRST) estimates a very high likelihood of exploitation in the next 30 days (2026-06-10). Priority blends CVSS, EPSS, KEV and public-exploit availability — operational prioritization, not a NIS2/DORA reporting determination.
Summary
Unauthenticated server-side template injection in ServiceNow UI macros that, chained with
CVE-2024-5217 / CVE-2024-5178, yields remote code execution and full database access. Added to the
CISA KEV catalog on 2024-07-29 (remediation due 2024-08-19) as an actively-exploited input-validation
flaw. Full technical detail, attack scenario, and regulatory mapping live in the cross-linked KB
article CVE-001 — this signature carries only the version matrix and the exposure-window detection
overlay.
Affected releases & fixed-in
| Release | Fixed in |
|---|---|
| Washington DC | Patch 1 Hot Fix 2b / Patch 2 Hot Fix 2 / Patch 3 Hot Fix 1 / Patch 4 |
| Vancouver | Patch 6 Hot Fix 2 / Patch 7 Hot Fix 3b / Patch 8 Hot Fix 4 / Patch 9 / Patch 10 |
| Utah | Patch 10 Hot Fix 3 / Patch 10a Hot Fix 2 |
Source & attribution
Per-release fixed-in from the ServiceNow-authored CVE Record (CNA shortName: SN) — affected[].versions[].lessThan boundaries (versionType: custom), https://cveawg.mitre.org/api/cve/CVE-2024-4879, retrieved 2026-06-08. The same patch matrix is in login-gated KB1645154/KB1644293; the public CVE Record is the citable source. Corroborated by NVD CPE enumeration + CISA KEV.
Regulatory mapping
- NIS2 Art.21§2(a)
- NIS2 Art.21§2(d)
- NIS2 Art.21§2(e)
- NIS2 Art.23§1
- DORA Art.9§1
- DORA Art.9§2
- DORA Art.17§1
- DORA RTS Art.10
- DORA RTS Art.11
- DORA RTS Art.22
- ISO A.8.8
- ISO A.8.9
- ISO A.8.28
Decision support, not a reporting determination.
References
Data: GitHub Advisory Database (CC-BY 4.0), NVD, the CISA KEV catalog, FIRST EPSS, Exploit-DB, and Nuclei templates.