CVE-2018-18389: Critical severity neo4j vulnerability
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-18389?
CVE-2018-18389 has a medium severity rating due to its potential to allow unauthorized access to the Neo4j Enterprise Database Server.
How do I fix CVE-2018-18389?
To fix CVE-2018-18389, upgrade Neo4j Enterprise Database Server to version 3.4.9 or later.
What versions of Neo4j are affected by CVE-2018-18389?
CVE-2018-18389 affects Neo4j Enterprise Database Server versions 3.4.0 to 3.4.8.
What impact does CVE-2018-18389 have on Neo4j users?
CVE-2018-18389 allows attackers to log into the Neo4j server using any valid username with an arbitrary password.
Is there a workaround for CVE-2018-18389?
No official workaround is provided for CVE-2018-18389; upgrading to a fixed version is the recommended course of action.