QID 981067

QID 981067: Java (maven) Security Update for org.neo4j:neo4j-enterprise (GHSA-h5f5-rj4r-42f6)

Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to refer to GHSA-h5f5-rj4r-42f6 for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981067

    Software Advisories
    Advisory ID Software Component Link
    GHSA-h5f5-rj4r-42f6 org.neo4j:neo4j-enterprise URL Logo github.com/advisories/GHSA-h5f5-rj4r-42f6