A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Graph_databse | Neo4j | 4.2 (including) | 4.2 (including) |
Graph_databse | Neo4j | 4.3 (including) | 4.3 (including) |