CVE-2021-34802

A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:neo4j:graph_databse:4.2:*:*:*:*:*:*:*
cpe:2.3:a:neo4j:graph_databse:4.3:*:*:*:*:*:*:*

History

04 Aug 2021, 00:52

Type Values Removed Values Added
CPE cpe:2.3:a:neo4j:graph_databse:4.3:*:*:*:*:*:*:*
cpe:2.3:a:neo4j:graph_databse:4.2:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.5
v3 : 8.8
CWE CWE-269
References (MISC) https://neo4j.com/developer/kb/neo4j-4-2-x-sec-vuln-fix/ - (MISC) https://neo4j.com/developer/kb/neo4j-4-2-x-sec-vuln-fix/ - Vendor Advisory
References (MISC) https://neo4j.com - (MISC) https://neo4j.com - Product

30 Jul 2021, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2021-07-30 14:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-34802

Mitre link : CVE-2021-34802

CVE.ORG link : CVE-2021-34802


JSON object : View

Products Affected

neo4j

  • graph_databse
CWE
CWE-269

Improper Privilege Management