Improper Privilege Management The advisory has been revoked - it doesn't affect any version of package org.neo4j:neo4j-util Open this link in a new tab


    Threat Intelligence

    EPSS
    0.05% (17th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGNEO4J-6814377
  • published 8 May 2024
  • disclosed 7 May 2024
  • credit Unknown

How to fix?

Upgrade org.neo4j:neo4j-util to version 5.19.0 or higher.

Amendment

This was deemed not a vulnerability.

Overview

Affected versions of this package are vulnerable to Improper Privilege Management due to the mishandling of IMMUTABLE privileges. An attacker can escalate privileges by exploiting this vulnerability.

Note:

  1. This is only exploitable with a legitimate admin account.
  2. This is only applicable for Enterprise edition.