CVE-2024-34517
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
- EPSS probability
- 0.63%
- CWE
- CWE-471
- Published
- 2024-05-07
- Last modified
- 2026-03-13
Affected products
- Neo4j Neo4j
Weakness type
Related vulnerabilities
- CVE-2026-50481 — Azure Active Directory Elevation of Privilege Vulnerability
- CVE-2026-54267 — Angular Client Hydration DOM Clobbering & Response-Cache Poisoning
- CVE-2026-44798 — Nautobot: GitRepository.current_head field should not be writable through REST API
- CVE-2026-8492 — Translate Drupal with GTranslate - Less critical - DOM clobbering / link manipulation - SA-CONTRIB-2026-035
- CVE-2025-33136 — IBM Aspera Faspex data modification
- CVE-2024-9876 — Application is vulnerable to Privilege escalation
- CVE-2024-55551 — An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject...
- CVE-2024-45672 — IBM Security Verify Bridge data manipulation