Record summary

CVE-2024-34517 has a selected CVSS score of 6.5 (medium).

Description

The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 22, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: unaffected, unknown

CVE List5.0.0 to < 5.19affected
5.0.0 to ≤ 5.19.0affected
GitHub Advisory5.0.0 to < 5.19.0 · Fixed in 5.19.0affected

References

6