CVE-2024-34517

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:community:*:*

History

21 Apr 2025, 14:12

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:* cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:community:*:*

25 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-269

13 Mar 2025, 04:15

Type Values Removed Values Added
Summary (en) The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE (en) The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
CWE CWE-471

11 Mar 2025, 19:55

Type Values Removed Values Added
First Time Neo4j neo4j
Neo4j
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.5
References () https://github.com/advisories/GHSA-p343-9qwp-pqxv - () https://github.com/advisories/GHSA-p343-9qwp-pqxv - Third Party Advisory
References () https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher - () https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher - Release Notes
References () https://neo4j.com/security/cve-2024-34517/ - () https://neo4j.com/security/cve-2024-34517/ - Vendor Advisory
References () https://trust.neo4j.com - () https://trust.neo4j.com - Product
CPE cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:*

Information

Published : 2024-05-07 18:15

Updated : 2025-04-21 14:12


NVD link : CVE-2024-34517

Mitre link : CVE-2024-34517

CVE.ORG link : CVE-2024-34517


JSON object : View

Products Affected

neo4j

  • neo4j
CWE
CWE-471

Modification of Assumed-Immutable Data (MAID)

NVD-CWE-Other