CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Snowpick: Open-source ServiceNow exposure scanner

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2980

As cited

Copy frozen at (site build).

cloud saas

Snowpick: Open-source ServiceNow exposure scanner

Bishop Fox developed Snowpick, an open-source Go tool that scans ServiceNow instances for exposure to unauthenticated access. During authorized penetration testing across 166 ServiceNow instances, the scanner found 31% were vulnerable and returned records or confirmations to unauthenticated requests. The firm published both the tool and its findings to help organizations identify and remediate this configuration weakness.

Why it matters: Practitioners managing ServiceNow deployments need to test their instances with Snowpick to identify whether knowledge bases and ticket systems are exposing sensitive information to unauthenticated users, as public portals are often misconfigured by default.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

cloud saas

Snowpick: Open-source ServiceNow exposure scanner

Bishop Fox developed Snowpick, an open-source Go tool that scans ServiceNow instances for exposure to unauthenticated access. During authorized penetration testing across 166 ServiceNow instances, the scanner found 31% were vulnerable and returned records or confirmations to unauthenticated requests. The firm published both the tool and its findings to help organizations identify and remediate this configuration weakness.

Why it matters: Practitioners managing ServiceNow deployments need to test their instances with Snowpick to identify whether knowledge bases and ticket systems are exposing sensitive information to unauthenticated users, as public portals are often misconfigured by default.

VendorsServiceNow
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary