The Cypher component in Neo4j 5.0.0 through 5.18 mishandles IMMUTABLE privileges in some situations where an attacker already has admin access.
The product does not properly protect an assumed-immutable element from being modified by an attacker.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Neo4j | Neo4j | 5.0.0 (including) | 5.19.0 (excluding) |