We're reclaiming inactive PDIs to keep them available for active builders. Learn what's changing, who's affected, and how to protect your work. Read More

Security Center - Escape Jelly Script

shruti758865
Tera Contributor

Hi everyone,

 

We are planning to enable the Escape Jelly Script hardening setting in ServiceNow Security Center.

 

Has anyone enabled this setting before? What areas should be tested, and are there any known impacts or issues after enabling it?

 

Thank you!

1 REPLY 1

Tanushree Maiti
Tera Patron

Hi @shruti758865 

 

For my client project , it has been set to true 9 yrs ago!

Escape jelly script [Updated in Security Center 1.3 and 1.5] 

 

Note: For security hardening changes, I generally prefer deploying them to UAT and leaving them there for about a month so business users have sufficient time to test and provide feedback before we proceed further.

Will suggest you -

  • Apply this setting in a Sub-Production (Dev/Test) environment first. 
  • Focus your regression testing on UI Pages, UI Macros, and content blocks that rely heavily on custom Jelly XML scripting
  • Utilize the studio->Code search tool to look for custom Jelly tags that pass unescaped variables
  •  
Please Accept the solution if it assisted you with your question & Mark this response as Helpful.
Regards
Tanushree Maiti
ServiceNow Technical Architect
LinkedIn: https://www.linkedin.com/in/tanushreemaiti