Answer in brief
CVE-2024-4879 records a High severity vulnerability in Jelly Template Injection Vulnerability in ServiceNow UI Macros. The current sources mark it as known exploited. The current feed maps ServiceNow/Now Platform (generic), servicenow/servicenow (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ServiceNow/Now Platform (generic), servicenow/servicenow (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ServiceNow/Now Platformgeneric | >=0 <Utah Patch 10 Hot Fix 3 || >=0 <Utah Patch 10a Hot Fix 2 || >=0 <Vancouver Patch 6 Hot Fix 2 || >=0 <Vancouver Patch 7 Hot Fix 3b || >=0 <Vancouver Patch 8 Hot Fix 4 || >=0 <Vancouver Patch 9 || >=0 <Vancouver Patch 10 || >=0 <Washington DC Patch 1 Hot Fix 2b || >=0 <Washington DC Patch 2 Hot Fix 2 || >=0 <Washington DC Patch 3 Hot Fix 1 || >=0 <Washington DC Patch 4 | Utah Patch 10 Hot Fix 3, Utah Patch 10a Hot Fix 2, Vancouver Patch 6 Hot Fix 2, Vancouver Patch 7 Hot Fix 3b, Vancouver Patch 8 Hot Fix 4, Vancouver Patch 9, Vancouver Patch 10, Washington DC Patch 1 Hot Fix 2b, Washington DC Patch 2 Hot Fix 2, Washington DC Patch 3 Hot Fix 1, Washington DC Patch 4 |
| servicenow/servicenowgeneric | >=0 <utah_patch_10_hot_fix_3 || >=0 <utah_patch_10a_hot_fix_2 || >=0 <vancouver_patch_6_hot_fix_2 || >=0 <vancouver_patch_7_hot_fix_3b || >=0 <vancouver_patch_8_hot_fix_4 || >=0 <vancouver_patch_9 || >=0 <vancouver_patch_10 || >=0 <washington_dc_patch_1_hot_fix_2b || >=0 <washington_dc_patch_2_hot_fix_2 || >=0 <washington_dc_patch_3_hot_fix_1 || >=0 <washington_dc_patch_4 | utah_patch_10_hot_fix_3, utah_patch_10a_hot_fix_2, vancouver_patch_6_hot_fix_2, vancouver_patch_7_hot_fix_3b, vancouver_patch_8_hot_fix_4, vancouver_patch_9, vancouver_patch_10, washington_dc_patch_1_hot_fix_2b, washington_dc_patch_2_hot_fix_2, washington_dc_patch_3_hot_fix_1, washington_dc_patch_4 |
Published upstream
Jul 10, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Jul 29, 2024
Evidence: source:kev:kev:kev:recordServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2024-4879 records a High severity vulnerability in Jelly Template Injection Vulnerability in ServiceNow UI Macros. The current sources mark it as known exploited. The current feed maps ServiceNow/Now Platform (generic), servicenow/servicenow (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. Known-exploitation status makes exposure review time-sensitive. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps ServiceNow/Now Platform (generic), servicenow/servicenow (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| ServiceNow/Now Platformgeneric | >=0 <Utah Patch 10 Hot Fix 3 || >=0 <Utah Patch 10a Hot Fix 2 || >=0 <Vancouver Patch 6 Hot Fix 2 || >=0 <Vancouver Patch 7 Hot Fix 3b || >=0 <Vancouver Patch 8 Hot Fix 4 || >=0 <Vancouver Patch 9 || >=0 <Vancouver Patch 10 || >=0 <Washington DC Patch 1 Hot Fix 2b || >=0 <Washington DC Patch 2 Hot Fix 2 || >=0 <Washington DC Patch 3 Hot Fix 1 || >=0 <Washington DC Patch 4 | Utah Patch 10 Hot Fix 3, Utah Patch 10a Hot Fix 2, Vancouver Patch 6 Hot Fix 2, Vancouver Patch 7 Hot Fix 3b, Vancouver Patch 8 Hot Fix 4, Vancouver Patch 9, Vancouver Patch 10, Washington DC Patch 1 Hot Fix 2b, Washington DC Patch 2 Hot Fix 2, Washington DC Patch 3 Hot Fix 1, Washington DC Patch 4 |
| servicenow/servicenowgeneric | >=0 <utah_patch_10_hot_fix_3 || >=0 <utah_patch_10a_hot_fix_2 || >=0 <vancouver_patch_6_hot_fix_2 || >=0 <vancouver_patch_7_hot_fix_3b || >=0 <vancouver_patch_8_hot_fix_4 || >=0 <vancouver_patch_9 || >=0 <vancouver_patch_10 || >=0 <washington_dc_patch_1_hot_fix_2b || >=0 <washington_dc_patch_2_hot_fix_2 || >=0 <washington_dc_patch_3_hot_fix_1 || >=0 <washington_dc_patch_4 | utah_patch_10_hot_fix_3, utah_patch_10a_hot_fix_2, vancouver_patch_6_hot_fix_2, vancouver_patch_7_hot_fix_3b, vancouver_patch_8_hot_fix_4, vancouver_patch_9, vancouver_patch_10, washington_dc_patch_1_hot_fix_2b, washington_dc_patch_2_hot_fix_2, washington_dc_patch_3_hot_fix_1, washington_dc_patch_4 |
Published upstream
Jul 10, 2024
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 21, 2025
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
May 24, 2026
Added to CISA KEV
Jul 29, 2024
Evidence: source:kev:kev:kev:recordServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow applied an update to hosted instances, and ServiceNow released the update to our partners and self-hosted customers. Listed below are the patches and hot fixes that address the vulnerability. If you have not done so already, we recommend applying security patches relevant to your instance as soon as possible.
Quoted source text, attributed separately from HOL analysis.