The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
{
"cpes": [
"cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:*",
"cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:community:*:*",
"cpe:2.3:a:neo4j:neo4j:*:*:*:*:community:*:*:*"
],
"severity": "Medium"
}