
Cloud Vulnerability DB
A community-led vulnerabilities database
The Cypher component in Neo4j between versions 5.0.0 and 5.19.0 contains a vulnerability related to the mishandling of IMMUTABLE privileges. This vulnerability was assigned CVE-2024-34517 and was discovered in early 2024, with the fix being released in version 5.19.0 (Neo4j Changelog, Neo4j Security).
The vulnerability is classified as a privilege management issue (CWE-269) and has received a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue specifically relates to how the Cypher component handles IMMUTABLE privileges, requiring the attacker to have legitimate admin privileges to exploit (CISA-ADP).
While specific impact details are limited in public sources, the high CVSS score indicates that successful exploitation could lead to significant security implications, particularly concerning privilege management within Neo4j installations. The vulnerability affects the confidentiality and integrity of the system, as indicated by the CVSS metrics (CISA-ADP).
The vulnerability requires legitimate admin privileges to exploit, which somewhat limits its potential abuse. The attack vector is network-accessible with low attack complexity and requires no user interaction, as indicated by the CVSS metrics (CISA-ADP).
The recommended mitigation is to upgrade existing Neo4j 5.18 installations to version 5.19.0 or later, which contains the fix for this vulnerability. While the vulnerability is not considered critical, upgrading is still recommended for affected installations (Neo4j Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."