CVE-2021-34371: Critical severity neo4j vulnerability
Neo4j through 3.4.18 (with the shell server enabled) exposes an RMI service that arbitrarily deserializes Java objects, e.g., through setSessionVariable. An attacker can abuse this for remote code execution because there are dependencies with exploitable gadget chains.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-34371?
CVE-2021-34371 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2021-34371?
To mitigate CVE-2021-34371, users should upgrade Neo4j to version 4.0 or later, which does not expose the vulnerable RMI service.
What are the potential impacts of CVE-2021-34371?
If exploited, CVE-2021-34371 can allow an attacker to execute arbitrary code on the server, leading to unauthorized access and data breaches.
Is my version of Neo4j affected by CVE-2021-34371?
Yes, any version of Neo4j up to and including 3.4.18 is affected by CVE-2021-34371 if the shell server is enabled.
Can CVE-2021-34371 be exploited remotely?
Yes, CVE-2021-34371 can be exploited remotely through the vulnerable RMI service exposed by the affected versions of Neo4j.