Security Center - Escape Jelly Script
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hi everyone,
We are planning to enable the Escape Jelly Script hardening setting in ServiceNow Security Center.
Has anyone enabled this setting before? What areas should be tested, and are there any known impacts or issues after enabling it?
Thank you!
1 REPLY 1
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
For my client project , it has been set to true 9 yrs ago!
Escape jelly script [Updated in Security Center 1.3 and 1.5]
Note: For security hardening changes, I generally prefer deploying them to UAT and leaving them there for about a month so business users have sufficient time to test and provide feedback before we proceed further.
Will suggest you -
- Apply this setting in a Sub-Production (Dev/Test) environment first.
- Focus your regression testing on UI Pages, UI Macros, and content blocks that rely heavily on custom Jelly XML scripting
- Utilize the studio->Code search tool to look for custom Jelly tags that pass unescaped variables
Please Accept the solution if it assisted you with your question & Mark this response as Helpful.
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti