{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2024-5890",
        "assignerOrgId": "303448ea-6ef3-4077-ad29-5c9bf253c375",
        "state": "PUBLISHED",
        "assignerShortName": "SN",
        "dateReserved": "2024-06-12T00:02:00.934Z",
        "datePublished": "2024-12-02T18:24:55.797Z",
        "dateUpdated": "2024-12-02T19:21:08.073Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "Now Platform",
                    "vendor": "ServiceNow",
                    "versions": [
                        {
                            "lessThan": "Utah Patch 8 Hot Fix 1",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Vancouver Patch 10",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Vancouver Patch 9",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        },
                        {
                            "lessThan": "Washington DC Early Access",
                            "status": "affected",
                            "version": "0",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Alexandre Rodrigo Da Silva"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "<span style=\"background-color: rgb(255, 255, 255);\">ServiceNow has addressed an HTML injection vulnerability that was </span><span style=\"background-color: rgb(255, 255, 255);\">identified</span><span style=\"background-color: rgb(255, 255, 255);\"> in the Now Platform. This vulnerability could</span><span style=\"background-color: rgb(255, 255, 255);\"> potentially</span><span style=\"background-color: rgb(255, 255, 255);\"> enable an unauthenticated user to </span><span style=\"background-color: rgb(255, 255, 255);\">modify</span> <span style=\"background-color: rgb(255, 255, 255);\">a</span> <span style=\"background-color: rgb(255, 255, 255);\">web </span><span style=\"background-color: rgb(255, 255, 255);\">page</span><span style=\"background-color: rgb(255, 255, 255);\"> or redirect users to another </span><span style=\"background-color: rgb(255, 255, 255);\">website</span><span style=\"background-color: rgb(255, 255, 255);\">.<br><br><span style=\"background-color: rgb(255, 255, 255);\">ServiceNow </span><span style=\"background-color: rgb(255, 255, 255);\">released</span> <span style=\"background-color: rgb(255, 255, 255);\">update</span><span style=\"background-color: rgb(255, 255, 255);\">s</span><span style=\"background-color: rgb(255, 255, 255);\">&nbsp;to customers</span><span style=\"background-color: rgb(255, 255, 255);\"> that addressed this vulnerability</span><span style=\"background-color: rgb(255, 255, 255);\">.  </span><span style=\"background-color: rgb(255, 255, 255);\">If you have not done so already, we recommend applying security patches relevant to your instance(s) as soon as possible</span><span style=\"background-color: rgb(255, 255, 255);\">.</span></span><br>"
                        }
                    ],
                    "value": "ServiceNow has addressed an HTML injection vulnerability that was identified in the Now Platform. This vulnerability could potentially enable an unauthenticated user to modify a web page or redirect users to another website.\n\nServiceNow released updates to customers that addressed this vulnerability.  If you have not done so already, we recommend applying security patches relevant to your instance(s) as soon as possible."
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "NETWORK",
                        "baseScore": 5.1,
                        "baseSeverity": "MEDIUM",
                        "privilegesRequired": "NONE",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "userInteraction": "ACTIVE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "NONE",
                        "vulnConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "LOW",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                },
                {
                    "cvssV3_1": {
                        "attackComplexity": "LOW",
                        "attackVector": "NETWORK",
                        "availabilityImpact": "NONE",
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "LOW",
                        "privilegesRequired": "NONE",
                        "scope": "UNCHANGED",
                        "userInteraction": "REQUIRED",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-79",
                            "description": "CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "303448ea-6ef3-4077-ad29-5c9bf253c375",
                "shortName": "SN",
                "dateUpdated": "2024-12-02T18:24:55.797Z"
            },
            "references": [
                {
                    "url": "https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1710511"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "HTML Injection in the Assessment plugin",
            "x_generator": {
                "engine": "Vulnogram 0.2.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "id": "CVE-2024-5890",
                                "role": "CISA Coordinator",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "version": "2.0.3",
                                "timestamp": "2024-12-02T19:20:40.477397Z"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2024-12-02T19:21:08.073Z"
                }
            }
        ]
    }
}