Description
Due to incorrect access control in Neo4j Enterprise Database Server 3.4.x before 3.4.9, the setting of LDAP for authentication with STARTTLS, and System Account for authorization, allows an attacker to log into the server by sending any valid username with an arbitrary password.
Remediation
References
https://github.com/neo4j/neo4j/issues/12047
Related Vulnerabilities
CVE-2022-39299 Vulnerability in npm package @node-saml/node-saml
CVE-2019-12043 Vulnerability in maven package org.webjars.bowergithub.jonschlinkert:remarkable
CVE-2020-2172 Vulnerability in maven package org.jenkins-ci.plugins:code-coverage-api
CVE-2021-22137 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2019-18797 Vulnerability in maven package org.webjars.npm:node-sass