GHSA-p343-9qwp-pqxv

Suggest an improvement
Source
https://github.com/advisories/GHSA-p343-9qwp-pqxv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/05/GHSA-p343-9qwp-pqxv/GHSA-p343-9qwp-pqxv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p343-9qwp-pqxv
Aliases
  • CVE-2024-34517
Related
Published
2024-05-07T18:30:34Z
Modified
2024-07-25T15:45:48.209144Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
Neo4j Cypher component mishandles IMMUTABLE privileges
Details

The Cypher component in Neo4j between v.5.0.0 and v.5.19.0 mishandles IMMUTABLE.

Database specific
{
    "nvd_published_at": "2024-05-07T18:15:08Z",
    "cwe_ids": [
        "CWE-269"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-05-07T19:59:41Z"
}
References

Affected packages

Maven / org.neo4j:neo4j-cypher

Package

Name
org.neo4j:neo4j-cypher
View open source insights on deps.dev
Purl
pkg:maven/org.neo4j/neo4j-cypher

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0
Fixed
5.19.0

Affected versions

5.*

5.1.0
5.2.0
5.3.0
5.4.0
5.5.0
5.6.0
5.7.0
5.8.0
5.9.0
5.10.0
5.11.0
5.12.0
5.13.0
5.14.0
5.15.0
5.16.0
5.17.0
5.18.0
5.18.1