Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://neo4j.com/security/cve-2025-11602 |
|
History
Fri, 31 Oct 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obtain one byte of information from previous connections. The attacker has no control over the information leaked in server responses. | |
| Title | Untargeted information leak in Bolt protocol handshake | |
| Weaknesses | CWE-226 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Neo4j
Published: 2025-10-31T10:20:17.254Z
Updated: 2025-10-31T11:37:44.777Z
Reserved: 2025-10-10T12:54:22.071Z
Link: CVE-2025-11602
Updated: 2025-10-31T11:36:18.345Z
Status : Received
Published: 2025-10-31T11:15:33.513
Modified: 2025-10-31T11:15:33.513
Link: CVE-2025-11602
No data.