{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Surfacing Security","title":"Chaining Three Bugs to Access All Your ServiceNow Data (Live Q&A)","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/42af6f31\"></iframe>","width":"100%","height":180,"duration":1781,"description":"On May 14th, 2024, we disclosed a chain of vulnerabilities to ServiceNow, resulting in 3 new CVEs. This series of security issues affected all Vancouver and Washington ServiceNow instances (around 42,000 globally), allowing an attacker to execute code on the instance.\nIn this live Q&A, Assetnote security researcher Adam Kues explains his approach to how he found these vulnerabilities, highlighted in our recent research post. He is joined by hosts, Michael Gianarakis and Shubham Shah.\nCongratulations to Adam on being credited with CVE-2024-4879, CVE-2024-5178, and CVE-2024-5217!\nTo learn more about Assetnote, visit https://www.assetnote.io/.","thumbnail_url":"https://img.transistorcdn.com/Jx76opOd-BvgfLHVKP77_8RjOd-Fqr7f2C1s_2hYrW8/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS82M2I3/M2IwYzNmNmQ5MjM0/MmJlYjNkNjk3ODI5/M2FiYS5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}