Privilege Escalation Affecting org.neo4j:neo4j-cypher package, versions [,4.2.8)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (43rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGNEO4J-1535217
  • published30 Jul 2021
  • disclosed30 Jul 2021
  • creditUnknown

Introduced: 30 Jul 2021

CVE-2021-34802  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade org.neo4j:neo4j-cypher to version 4.2.8 or higher.

Overview

Affected versions of this package are vulnerable to Privilege Escalation. A failure in resetting the security context in some transaction actions in Neo4j Graph Database could allow authenticated users to execute commands with elevated privileges.

References

CVSS Scores

version 3.1