Skip to main content

SNOW-22.1: SSRF via Dynamic RESTMessageV2 Endpoint

๐Ÿšจ Critical ยท ServiceNow SSRF

Detects agent scripts using sn_ws.RESTMessageV2 with dynamic endpoint parameters derived from user input, enabling SSRF against internal services.

Detailsโ€‹

FieldValue
Rule IDSNOW-22.1
SeverityCritical
CategoryServiceNow SSRF
Platformsservicenow

Remediationโ€‹

Refer to the SquireX documentation for remediation guidance specific to SNOW-22.1.

See Alsoโ€‹