CVE-2024-34517

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:community:*:*

History

21 Apr 2025, 14:12

Type Values Removed Values Added
CPE cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:* cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:community:*:*
CWE NVD-CWE-Other

25 Mar 2025, 15:15

Type Values Removed Values Added
CWE CWE-269

13 Mar 2025, 04:15

Type Values Removed Values Added
Summary (en) The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE (en) The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
CWE CWE-471

11 Mar 2025, 19:55

Type Values Removed Values Added
References () https://github.com/advisories/GHSA-p343-9qwp-pqxv - () https://github.com/advisories/GHSA-p343-9qwp-pqxv - Third Party Advisory
References () https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher - () https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher - Release Notes
References () https://neo4j.com/security/cve-2024-34517/ - () https://neo4j.com/security/cve-2024-34517/ - Vendor Advisory
References () https://trust.neo4j.com - () https://trust.neo4j.com - Product
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 6.5
CPE cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:*
First Time Neo4j neo4j
Neo4j

21 Nov 2024, 09:18

Type Values Removed Values Added
References () https://github.com/advisories/GHSA-p343-9qwp-pqxv - () https://github.com/advisories/GHSA-p343-9qwp-pqxv -
References () https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher - () https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog#cypher -
References () https://neo4j.com/security/cve-2024-34517/ - () https://neo4j.com/security/cve-2024-34517/ -
References () https://trust.neo4j.com - () https://trust.neo4j.com -

03 Jul 2024, 02:00

Type Values Removed Values Added
CWE CWE-269
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

05 Jun 2024, 20:15

Type Values Removed Values Added
Summary (en) The Cypher component in Neo4j before 5.19.0 mishandles IMMUTABLE privileges. (en) The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE

14 May 2024, 15:39

Type Values Removed Values Added
Summary
  • (es) El componente Cypher en Neo4j anterior a 5.19.0 maneja mal los privilegios IMMUTABLES.
References
  • () https://github.com/advisories/GHSA-p343-9qwp-pqxv -

07 May 2024, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-07 18:15

Updated : 2025-04-21 14:12


NVD link : CVE-2024-34517

Mitre link : CVE-2024-34517

CVE.ORG link : CVE-2024-34517


JSON object : View

Products Affected

neo4j

  • neo4j
CWE
CWE-471

Modification of Assumed-Immutable Data (MAID)

NVD-CWE-Other