Vulnerability Details CVE-2024-34517
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 48.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-34517
-
cpe:2.3:a:neo4j:neo4j:5.0.0
-
cpe:2.3:a:neo4j:neo4j:5.1.0
-
cpe:2.3:a:neo4j:neo4j:5.10.0
-
cpe:2.3:a:neo4j:neo4j:5.11.0
-
cpe:2.3:a:neo4j:neo4j:5.12.0
-
cpe:2.3:a:neo4j:neo4j:5.13.0
-
cpe:2.3:a:neo4j:neo4j:5.14.0
-
cpe:2.3:a:neo4j:neo4j:5.15.0
-
cpe:2.3:a:neo4j:neo4j:5.16.0
-
cpe:2.3:a:neo4j:neo4j:5.17.0
-
cpe:2.3:a:neo4j:neo4j:5.18.0
-
cpe:2.3:a:neo4j:neo4j:5.18.1
-
cpe:2.3:a:neo4j:neo4j:5.2.0
-
cpe:2.3:a:neo4j:neo4j:5.3.0
-
cpe:2.3:a:neo4j:neo4j:5.4.0
-
cpe:2.3:a:neo4j:neo4j:5.5.0
-
cpe:2.3:a:neo4j:neo4j:5.6.0
-
cpe:2.3:a:neo4j:neo4j:5.7.0
-
cpe:2.3:a:neo4j:neo4j:5.8.0
-
cpe:2.3:a:neo4j:neo4j:5.9.0