Hacker News new | ask | show | jobs
by manvillej 1082 days ago
ServiceNow ships major upgrades twice a year and patches every month. It means that they could genuinely not figure out how to remediate this quickly and quietly without disrupting ongoing contract negotiations. It means that even with that, they couldn't fix it for a whole year.

They negotiate multiyear contracts. they're investing into government and healthcare services.

1 comments

I have to correct myself. Apparently the vulnerability was patched in San Diego patch 7 which was release on September 1st 2022. It wasn't disclosed until June 2023.

I am still mad they didn't release it as a hotfix, but that meant they couldn't sneak it under the radar.