GHSA-2w4h-f44w-968f

Suggest an improvement
Source
https://github.com/advisories/GHSA-2w4h-f44w-968f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-2w4h-f44w-968f/GHSA-2w4h-f44w-968f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2w4h-f44w-968f
Aliases
  • CVE-2021-34802
Published
2022-05-24T19:09:23Z
Modified
2024-02-21T05:33:41.037562Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Improper Privilege Management in Neo4j Graph Database
Details

A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 could allow authenticated users to execute commands with elevated privileges.

Database specific
{
    "nvd_published_at": "2021-07-30T14:15:00Z",
    "cwe_ids": [
        "CWE-269"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-06-21T20:12:33Z"
}
References

Affected packages

Maven / org.neo4j:neo4j-kernel

Package

Name
org.neo4j:neo4j-kernel
View open source insights on deps.dev
Purl
pkg:maven/org.neo4j/neo4j-kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Fixed
4.2.8

Affected versions

4.*

4.2.0
4.2.1
4.2.2
4.2.3
4.2.4
4.2.5
4.2.6
4.2.7

Database specific

{
    "last_known_affected_version_range": "<= 4.2.7"
}