Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2024-34517
Java vulnerability analysis and mitigation

Overview

The Cypher component in Neo4j between versions 5.0.0 and 5.19.0 contains a vulnerability related to the mishandling of IMMUTABLE privileges. This vulnerability was assigned CVE-2024-34517 and was discovered in early 2024, with the fix being released in version 5.19.0 (Neo4j Changelog, Neo4j Security).

Technical details

The vulnerability is classified as a privilege management issue (CWE-269) and has received a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue specifically relates to how the Cypher component handles IMMUTABLE privileges, requiring the attacker to have legitimate admin privileges to exploit (CISA-ADP).

Impact

While specific impact details are limited in public sources, the high CVSS score indicates that successful exploitation could lead to significant security implications, particularly concerning privilege management within Neo4j installations. The vulnerability affects the confidentiality and integrity of the system, as indicated by the CVSS metrics (CISA-ADP).

Exploitability

The vulnerability requires legitimate admin privileges to exploit, which somewhat limits its potential abuse. The attack vector is network-accessible with low attack complexity and requires no user interaction, as indicated by the CVSS metrics (CISA-ADP).

Mitigation and workarounds

The recommended mitigation is to upgrade existing Neo4j 5.18 installations to version 5.19.0 or later, which contains the fix for this vulnerability. While the vulnerability is not considered critical, upgrading is still recommended for affected installations (Neo4j Security).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-53837CRITICAL9.9
  • Java logoJava
  • org.xwiki.rendering:xwiki-rendering-xml
NoYesSep 18, 2026
CVE-2026-77615HIGH8.7
  • JavaScript logoJavaScript
  • org.opencastproject:opencast-engage-paella-player-7
NoYesSep 17, 2026
CVE-2026-54148HIGH8.1
  • Java logoJava
  • org.http4k:http4k-security-digest
NoYesSep 18, 2026
CVE-2026-85058HIGH7.5
  • Java logoJava
  • io.moquette:moquette-broker
NoYesSep 18, 2026
CVE-2026-54147MEDIUM6.5
  • Java logoJava
  • org.http4k:http4k-security-digest
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management