CVE-2021-34802: High severity neo4j vulnerability
Published Jul 27, 2021
·Updated
A failure in resetting the security context in some transaction actions in Neo4j Graph Database 4.2 and 4.3 could allow authenticated users to execute commands with elevated privileges.
Affected Software
2 affected components
Neo4j Graph Databse=4.2
Neo4j Graph Databse=4.3
Event History
Jul 27, 2021
CVE Published
via MITRE·11:25 AM
Data Sourced
via MITRE·11:25 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-34802?
CVE-2021-34802 is considered a high severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2021-34802?
To fix CVE-2021-34802, upgrade to Neo4j Graph Database version 4.4 or later.
3
Who is affected by CVE-2021-34802?
CVE-2021-34802 affects users of Neo4j Graph Database versions 4.2 and 4.3.
4
What actions could be exploited in CVE-2021-34802?
Authenticated users could exploit CVE-2021-34802 by executing commands with elevated privileges.
5
When was CVE-2021-34802 disclosed?
CVE-2021-34802 was disclosed publicly in June 2021.