{"id":"GHSA-x626-q4v7-7xc6","summary":"Neo4J vulnerable to Cross-Site Request Forgery","details":"Multiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of administrators for requests that execute arbitrary code, as demonstrated by a request to (1) db/data/ext/GremlinPlugin/graphdb/execute_script or (2) db/manage/server/console/.","aliases":["CVE-2013-7259"],"modified":"2025-04-14T16:12:07.787603Z","published":"2022-05-17T04:38:50Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-04-14T15:44:43Z","nvd_published_at":"2014-04-29T14:38:00Z","cwe_ids":["CWE-352","CWE-78"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7259"},{"type":"WEB","url":"https://github.com/neo4j/neo4j/issues/2826"},{"type":"WEB","url":"https://github.com/neo4j/neo4j/commit/40ad76078a25666d8b218772b6491fb443020df9"},{"type":"PACKAGE","url":"https://github.com/neo4j/neo4j"},{"type":"WEB","url":"https://github.com/o2platform/DefCon_RESTing/tree/master/Live-Demos/Neo4j"},{"type":"WEB","url":"https://web.archive.org/web/20131017043717/http://blog.diniscruz.com/2013/08/neo4j-csrf-payload-to-start-processes.html"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/01/03/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/01/03/8"}],"affected":[{"package":{"name":"org.neo4j:neo4j","ecosystem":"Maven","purl":"pkg:maven/org.neo4j/neo4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.2.0-M01"}]}],"versions":["1.2","1.2.M01","1.2.M02","1.2.M03","1.2.M04","1.2.M05","1.2.M06","1.3","1.3.M01","1.3.M02","1.3.M03","1.3.M04","1.3.M05","1.4","1.4.1","1.4.2","1.4.M01","1.4.M02","1.4.M03","1.4.M04","1.4.M05","1.4.M06","1.5","1.5.1","1.5.2","1.5.3","1.5.M01","1.5.M02","1.6","1.6.1","1.6.2","1.6.3","1.6.M01","1.6.M02","1.6.M03","1.7","1.7.1","1.7.2","1.7.M01","1.7.M02","1.7.M03","1.8","1.8.1","1.8.2","1.8.3","1.8.M01","1.8.M02","1.8.M03","1.8.M04","1.8.M05","1.8.M06","1.8.M07","1.8.RC1","1.9","1.9.1","1.9.2","1.9.3","1.9.4","1.9.5","1.9.6","1.9.7","1.9.8","1.9.9","1.9.M01","1.9.M02","1.9.M03","1.9.M04","1.9.M05","1.9.RC1","1.9.RC2","2.0.0","2.0.0-M01","2.0.0-M02","2.0.0-M03","2.0.0-M04","2.0.0-M05","2.0.0-M06","2.0.0-RC1","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.1.0","2.1.0-M01","2.1.0-M02","2.1.0-RC1","2.1.0-RC2","2.1.1","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x626-q4v7-7xc6/GHSA-x626-q4v7-7xc6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}