|
| 1 | +<?xml version="1.0" encoding="UTF-8"?><record_update table="scan_table_check"> |
| 2 | + <scan_table_check action="DELETE"> |
| 3 | + <active>true</active> |
| 4 | + <advanced>false</advanced> |
| 5 | + <category>security</category> |
| 6 | + <conditions table="sys_security_acl">scriptISNOTEMPTY^advanced=false^EQ<item endquery="false" field="script" goto="false" newquery="false" operator="ISNOTEMPTY" or="false" value=""/> |
| 7 | + <item endquery="false" field="advanced" goto="false" newquery="false" operator="=" or="false" value="false"/> |
| 8 | + <item endquery="true" field="" goto="false" newquery="false" operator="=" or="false" value=""/> |
| 9 | + </conditions> |
| 10 | + <description>Script in ACL executes even if Advanced is unchecked. This may lead to confusion and unexpected behavior, coming from the script being hidden on the form but executed.</description> |
| 11 | + <documentation_url>https://docs.servicenow.com/bundle/utah-platform-security/page/administer/contextual-security/task/t_CreateAnACLRule.html</documentation_url> |
| 12 | + <finding_type>scan_finding</finding_type> |
| 13 | + <name>Script in ACL when Advanced is unchecked</name> |
| 14 | + <priority>1</priority> |
| 15 | + <resolution_details>Either check Advanced or Remove the script from the ACL, while making sure to maintain the same ACL result.</resolution_details> |
| 16 | + <run_condition/> |
| 17 | + <score_max>100</score_max> |
| 18 | + <score_min>0</score_min> |
| 19 | + <score_scale>1</score_scale> |
| 20 | + <script><![CDATA[(function (engine) { |
| 21 | +
|
| 22 | + // Add your code here |
| 23 | +
|
| 24 | +})(engine);]]></script> |
| 25 | + <short_description>Script in ACL executes even if Advanced is unchecked.</short_description> |
| 26 | + <sys_class_name>scan_table_check</sys_class_name> |
| 27 | + <sys_created_by>admin</sys_created_by> |
| 28 | + <sys_created_on>2023-10-04 20:36:19</sys_created_on> |
| 29 | + <sys_id>eb21adf797697110710650081153af9c</sys_id> |
| 30 | + <sys_mod_count>0</sys_mod_count> |
| 31 | + <sys_name>Script in ACL when Advanced is unchecked</sys_name> |
| 32 | + <sys_package display_value="Example Instance Checks" source="x_appe_exa_checks">ca8467c41b9abc10ce0f62c3b24bcbaa</sys_package> |
| 33 | + <sys_policy/> |
| 34 | + <sys_scope display_value="Example Instance Checks">ca8467c41b9abc10ce0f62c3b24bcbaa</sys_scope> |
| 35 | + <sys_update_name>scan_table_check_eb21adf797697110710650081153af9c</sys_update_name> |
| 36 | + <sys_updated_by>admin</sys_updated_by> |
| 37 | + <sys_updated_on>2023-10-04 20:36:19</sys_updated_on> |
| 38 | + <table>sys_security_acl</table> |
| 39 | + <use_manifest>false</use_manifest> |
| 40 | + </scan_table_check> |
| 41 | +<sys_update_version action="INSERT_OR_UPDATE"> |
| 42 | + <action>DELETE</action> |
| 43 | + <application display_value="Example Instance Checks">ca8467c41b9abc10ce0f62c3b24bcbaa</application> |
| 44 | + <file_path/> |
| 45 | + <instance_id>7c7abcb4db5631d82f082a5913961914</instance_id> |
| 46 | + <instance_name>dev200172</instance_name> |
| 47 | + <name>scan_table_check_eb21adf797697110710650081153af9c</name> |
| 48 | + <payload><?xml version="1.0" encoding="UTF-8"?><record_update table="scan_table_check"> |
| 49 | + <scan_table_check action="INSERT_OR_UPDATE"> |
| 50 | + <active>true</active> |
| 51 | + <advanced>false</advanced> |
| 52 | + <category>security</category> |
| 53 | + <conditions table="sys_security_acl">scriptISNOTEMPTY^advanced=false^EQ<item endquery="false" field="script" goto="false" newquery="false" operator="ISNOTEMPTY" or="false" value=""/> |
| 54 | + <item endquery="false" field="advanced" goto="false" newquery="false" operator="=" or="false" value="false"/> |
| 55 | + <item endquery="true" field="" goto="false" newquery="false" operator="=" or="false" value=""/> |
| 56 | + </conditions> |
| 57 | + <description>Script in ACL executes even if Advanced is unchecked. This may lead to confusion and unexpected behavior, coming from the script being hidden on the form but executed.</description> |
| 58 | + <documentation_url>https://docs.servicenow.com/bundle/utah-platform-security/page/administer/contextual-security/task/t_CreateAnACLRule.html</documentation_url> |
| 59 | + <finding_type>scan_finding</finding_type> |
| 60 | + <name>Script in ACL when Advanced is unchecked</name> |
| 61 | + <priority>1</priority> |
| 62 | + <resolution_details>Either check Advanced or Remove the script from the ACL, while making sure to maintain the same ACL result.</resolution_details> |
| 63 | + <run_condition/> |
| 64 | + <score_max>100</score_max> |
| 65 | + <score_min>0</score_min> |
| 66 | + <score_scale>1</score_scale> |
| 67 | + <script><![CDATA[(function (engine) { |
| 68 | + |
| 69 | + // Add your code here |
| 70 | + |
| 71 | +})(engine);]]></script> |
| 72 | + <short_description>Script in ACL executes even if Advanced is unchecked.</short_description> |
| 73 | + <sys_class_name>scan_table_check</sys_class_name> |
| 74 | + <sys_created_by>admin</sys_created_by> |
| 75 | + <sys_created_on>2023-10-04 20:36:19</sys_created_on> |
| 76 | + <sys_id>eb21adf797697110710650081153af9c</sys_id> |
| 77 | + <sys_mod_count>0</sys_mod_count> |
| 78 | + <sys_name>Script in ACL when Advanced is unchecked</sys_name> |
| 79 | + <sys_package display_value="Example Instance Checks" source="x_appe_exa_checks">ca8467c41b9abc10ce0f62c3b24bcbaa</sys_package> |
| 80 | + <sys_policy/> |
| 81 | + <sys_scope display_value="Example Instance Checks">ca8467c41b9abc10ce0f62c3b24bcbaa</sys_scope> |
| 82 | + <sys_update_name>scan_table_check_eb21adf797697110710650081153af9c</sys_update_name> |
| 83 | + <sys_updated_by>admin</sys_updated_by> |
| 84 | + <sys_updated_on>2023-10-04 20:36:19</sys_updated_on> |
| 85 | + <table>sys_security_acl</table> |
| 86 | + <use_manifest>false</use_manifest> |
| 87 | + </scan_table_check> |
| 88 | +</record_update></payload> |
| 89 | + <payload_hash>1356454248</payload_hash> |
| 90 | + <record_name>Script in ACL when Advanced is unchecked</record_name> |
| 91 | + <reverted_from/> |
| 92 | + <source>f587d90bc3dd1250faa4bd33e4013147</source> |
| 93 | + <source_table>sys_upgrade_history</source_table> |
| 94 | + <state>previous</state> |
| 95 | + <sys_created_by>admin</sys_created_by> |
| 96 | + <sys_created_on>2024-10-21 18:01:38</sys_created_on> |
| 97 | + <sys_id>2387514bc3dd1250faa4bd33e40131fe</sys_id> |
| 98 | + <sys_mod_count>0</sys_mod_count> |
| 99 | + <sys_recorded_at>192b03de1990000001</sys_recorded_at> |
| 100 | + <sys_updated_by>admin</sys_updated_by> |
| 101 | + <sys_updated_on>2024-10-21 18:01:38</sys_updated_on> |
| 102 | + <type>Table Check</type> |
| 103 | + <update_guid>2f87514b95dd1250d8d7157d4a5955fd</update_guid> |
| 104 | + <update_guid_history>2f87514b95dd1250d8d7157d4a5955fd:0,e267d9c752dd1250e0ae7bf3aa17e665:-2023533997,eea83dedc1c5de50dcb00ddc90e599ae:1356454248</update_guid_history> |
| 105 | + </sys_update_version> |
| 106 | + <sys_metadata_delete action="INSERT_OR_UPDATE"> |
| 107 | + <sys_audit_delete display_value="Script in ACL when Advanced is unchecked">1379110bc3dd1250faa4bd33e4013183</sys_audit_delete> |
| 108 | + <sys_class_name>sys_metadata_delete</sys_class_name> |
| 109 | + <sys_created_by>admin</sys_created_by> |
| 110 | + <sys_created_on>2024-10-21 18:10:05</sys_created_on> |
| 111 | + <sys_db_object display_value="" name="scan_table_check">scan_table_check</sys_db_object> |
| 112 | + <sys_id>6497f98bb9dc40a28cfd0e9f7ed83e24</sys_id> |
| 113 | + <sys_metadata>eb21adf797697110710650081153af9c</sys_metadata> |
| 114 | + <sys_mod_count>0</sys_mod_count> |
| 115 | + <sys_name>Script in ACL when Advanced is unchecked</sys_name> |
| 116 | + <sys_package display_value="Example Instance Checks" source="x_appe_exa_checks">ca8467c41b9abc10ce0f62c3b24bcbaa</sys_package> |
| 117 | + <sys_parent/> |
| 118 | + <sys_policy/> |
| 119 | + <sys_scope display_value="Example Instance Checks">ca8467c41b9abc10ce0f62c3b24bcbaa</sys_scope> |
| 120 | + <sys_scope_delete display_value="">30a78b9b9290467a96959a65d2b2d304</sys_scope_delete> |
| 121 | + <sys_update_name>scan_table_check_eb21adf797697110710650081153af9c</sys_update_name> |
| 122 | + <sys_update_version display_value="scan_table_check_eb21adf797697110710650081153af9c">2387514bc3dd1250faa4bd33e40131fe</sys_update_version> |
| 123 | + <sys_updated_by>admin</sys_updated_by> |
| 124 | + <sys_updated_on>2024-10-21 18:10:05</sys_updated_on> |
| 125 | + </sys_metadata_delete> |
| 126 | +</record_update> |
0 commit comments