Skip to content

CVE-2024-34517 @ Maven-org.neo4j:neo4j-cypher-1.8.1 #16000

@cx-nitzan-massader

Description

@cx-nitzan-massader

Checkmarx (SCA): Vulnerable Package
Vulnerability: Read More about CVE-2024-34517
Checkmarx Project: AsafOrgTesting/Sast-Sca-Test-Repo
Repository URL: https://github.com/AsafOrgTesting/Sast-Sca-Test-Repo
Branch: master
Scan ID: 381445f1-c79b-4b6f-9733-56cc146401f9


The "Cypher" component in Neo4j versions prior to 5.19.0 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.


Additional Info
Attack vector: NETWORK
Attack complexity: LOW
Confidentiality impact: HIGH
Availability impact: NONE
Remediation Upgrade Recommendation: 4.4.35

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions