CVE-2024-34517

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:community:*:*

History

21 Apr 2025, 14:12

Type Values Removed Values Added
CWE NVD-CWE-Other
CPE cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:* cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:community:*:*

13 Mar 2025, 04:15

Type Values Removed Values Added
Summary The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

11 Mar 2025, 19:55

Type Values Removed Values Added
First Time Neo4j neo4j
Neo4j
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:*
References () https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher - () https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher - Release Notes
References () https://github.com/advisories/GHSA-p343-9qwp-pqxv - () https://github.com/advisories/GHSA-p343-9qwp-pqxv - Third Party Advisory
References () https://neo4j.com/security/cve-2024-34517/ - () https://neo4j.com/security/cve-2024-34517/ - Vendor Advisory
References () https://trust.neo4j.com - () https://trust.neo4j.com - Product

05 Jun 2024, 20:15

Type Values Removed Values Added
Summary The Cypher component in Neo4j before 5.19.0 mishandles IMMUTABLE privileges. The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE

14 May 2024, 15:39

Type Values Removed Values Added
References
  • () https://github.com/advisories/GHSA-p343-9qwp-pqxv -

07 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-07 18:15

Updated : 2025-04-21 14:12


NVD link : CVE-2024-34517

Mitre link : CVE-2024-34517


JSON object : View

Products Affected

neo4j

  • neo4j