nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-8923 CVE-2024-8923
CRITICAL
Sandbox Escape in Now Platform
Record summary
CVE-2024-8923 has a selected CVSS score of 9.3 (critical).
Description
ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 30, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Now PlatformBrowse ServiceNow / Now PlatformDefault status: unaffected | CVE List | Before Vancouver Patch 9 Hot Fix 2a | affected |
| Before Vancouver Patch 10 | affected | ||
| Before Washington DC Patch 4 Hot Fix 1a | affected | ||
| Before Washington DC Patch 5 | affected | ||
| Before Xanadu GA Release | affected | ||
servicenowBrowse servicenow / servicenowDefault status: unknown | CVE List | Vancouver to < Vancouver Patch 9 Hot Fix 2a | affected |
| Vancouver to < Vancouver Patch 10 | affected | ||
| Washington_DC to < Washington DC Patch 4 Hot Fix 1a | affected | ||
| Washington_DC to < Washington DC Patch 5 | affected | ||
| Xanadu to < Xanadu GA Release | affected |
References
2support.servicenow.com
https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1706070