Security
Loading…

CVE-2024-5217

UNKNOWNKnown Exploited
Description

ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could exploit this vulnerability to execute code remotely.

Timeline
Published:July 29th, 2024 12:00 AM
Last modified:July 29th, 2024 12:00 AM
Added to KEV:July 29th, 2024
CVSS Scoring

No CVSS v3 score available

Affected Software
From NVD CPE configuration data

Vendors

ServiceNow

Products

Utah, Vancouver, and Washington DC Now Platform
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports

No references available.

Source: CISA KEV + NVD · Data may lag official sources by up to one minute