Description
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Problem types
CWE-471 Modification of Assumed-Immutable Data (MAID)
Product status
5.0.0 before 5.19
References
neo4j.com/security/cve-2024-34517/
github.com/neo4j/neo4j/wiki/Neo4j-5-changelog
github.com/advisories/GHSA-p343-9qwp-pqxv