The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
{
"severity": "Medium",
"cpes": [
"cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:*:*:*",
"cpe:2.3:a:neo4j:neo4j:*:*:*:*:*:community:*:*"
]
}