The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-269 |
Thu, 13 Mar 2025 04:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE | The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access. |
Weaknesses | CWE-471 |
Tue, 11 Mar 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:neo4j:neo4j:5.0.0:*:*:*:*:*:*:* | |
Metrics |
ssvc
|
Tue, 11 Mar 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Neo4j
Neo4j neo4j |
|
CPEs | cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:* | |
Vendors & Products |
Neo4j
Neo4j neo4j |
|
Metrics |
cvssV3_1
|
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2024-05-07T00:00:00.000Z
Updated: 2025-03-25T14:33:17.720Z
Reserved: 2024-05-05T00:00:00.000Z
Link: CVE-2024-34517

Updated: 2024-08-02T02:51:11.588Z

Status : Modified
Published: 2024-05-07T18:15:08.467
Modified: 2025-03-25T15:15:21.807
Link: CVE-2024-34517

No data.