CVE-2024-34517: NEO4J
Medium severity, CVSS 6.5. EPSS: 0.6% chance of exploitation in the next 30 days.
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Affected products
- NEO4J NEO4J: from 5.0.0, before 5.19.0 (fixed in 5.19.0)
Published 2024-05-07. Last modified 2026-08-28.