6.5

CVE-2024-34517

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Neo4jNeo4j SwPlatformcommunity Version >= 5.0.0 < 5.19.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.63% 0.452
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 1.2 5.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
cve@mitre.org 6.5 1.2 5.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
CWE-471 Modification of Assumed-Immutable Data (MAID)

The product does not properly protect an assumed-immutable element from being modified by an attacker.

https://github.com/advisories/GHSA-p343-9qwp-pqxv
Third Party Advisory
https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher
Release Notes
https://neo4j.com/security/cve-2024-34517/
Vendor Advisory
https://trust.neo4j.com
Product