github.com
https://github.com/advisories/GHSA-p343-9qwp-pqxv CVE-2024-34517
MEDIUM
Neo4j Cypher component mishandles IMMUTABLE privileges
Record summary
CVE-2024-34517 has a selected CVSS score of 6.5 (medium).
Description
The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 22, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Neo4jBrowse Neo4j / Neo4jDefault status: unaffected, unknown | CVE List | 5.0.0 to < 5.19 | affected |
| 5.0.0 to ≤ 5.19.0 | affected | ||
org.neo4j:neo4j-cypherBrowse Maven / org.neo4j:neo4j-cypher | GitHub Advisory | 5.0.0 to < 5.19.0 · Fixed in 5.19.0 | affected |
References
6github.com
https://github.com/neo4j/neo4j github.com
https://github.com/neo4j/neo4j/wiki/Neo4j-5-changelog neo4j.com
https://neo4j.com/security/cve-2024-34517 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-34517 trust.neo4j.com
https://trust.neo4j.com/