ServiceNow Vulnerabilities and Affected Products
Vulnerabilities associated with Jenkins plug-in for ServiceNow DevOps.
Products
Clear product- Now Platform11 vulnerabilities
- servicenow5 vulnerabilities
- ServiceNow AI Platform5 vulnerabilities
- Jenkins plug-in for ServiceNow DevOps2 vulnerabilities
- Utah, Vancouver, and Washington DC Now Platform2 vulnerabilities
- Now Assist AI Agents1 vulnerability
- Now User Experience1 vulnerability
- ServiceNow Records1 vulnerability
- Virtual Agent API1 vulnerability
- Washington DC, Vancouver, and Utah Now Platform1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-3442HIGH | Missing Authorization in Jenkins plug-in for ServiceNow DevOpsA missing authorization vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform. CWE-862Jul 26, 2023 | CVSS7.7v3.1 | EPSS0.711% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-3414MEDIUM | Cross-Site Request Forgery (CSRF) in Jenkins Plug-in for ServiceNow DevOpsA cross-site request forgery vulnerability exists in versions of the Jenkins Plug-in for ServiceNow DevOps prior to 1.38.1 that, if exploited successfully, could cause the unwanted exposure of sensitive information. To address this issue, apply the 1.38.1 version of the Jenkins plug-in for ServiceNow DevOps on your Jenkins server. No changes are required on your instances of the Now Platform. | CVSS6.1v3.1 | EPSS0.413% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |