QID 981067
QID 981067: Java (maven) Security Update for org.neo4j:neo4j-enterprise (GHSA-h5f5-rj4r-42f6)
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h5f5-rj4r-42f6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-h5f5-rj4r-42f6 -
github.com/advisories/GHSA-h5f5-rj4r-42f6
CVEs related to QID 981067
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h5f5-rj4r-42f6 | org.neo4j:neo4j-enterprise |
|