Vulnerability Description
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Neo4J | Neo4J | >= 5.0.0, < 5.19.0 |
Related Weaknesses (CWE)
References
- https://github.com/advisories/GHSA-p343-9qwp-pqxvThird Party Advisory
- https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypherRelease Notes
- https://neo4j.com/security/cve-2024-34517/Vendor Advisory
- https://trust.neo4j.comProduct
- https://github.com/advisories/GHSA-p343-9qwp-pqxvThird Party Advisory
- https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypherRelease Notes
- https://neo4j.com/security/cve-2024-34517/Vendor Advisory
- https://trust.neo4j.comProduct
FAQ
What is CVE-2024-34517?
CVE-2024-34517 is a vulnerability with a CVSS score of 6.5 (MEDIUM). The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
How severe is CVE-2024-34517?
CVE-2024-34517 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-34517?
Check the references section above for vendor advisories and patch information. Affected products include: Neo4J Neo4J.