The vulnerability stems from flaws in the plugin's handling of "direct request" mode, where it accepted requests without proper cryptographic verification.
ServiceNow has addressed a critical vulnerability within its AI Platform that could have allowed threat actors to impersonate users and execute arbitrary actions.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.