A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NNeo4j Awesome Procedures
APPNeo4J< 3.5.0.174.2.0.0 – 4.2.10 (excl.)4.3.0.0 – 4.3.0.4 (excl.)4.4.0.0 – 4.4.0.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
Related vulnerabilities
CVE-2021-34371CRITICAL9.8PL ✓same vendor
RCE przez deserializację RMI w Neo4j (shell server)
CVE-2018-1000820CRITICAL10.0PL ✓same vendor
XXE w Neo4j APOC Procedures — ujawnienie danych, SSRF, DoS
CVE-2018-18389CRITICAL9.8PL ✓same vendor
Neo4j Enterprise: ominięcie uwierzytelnienia LDAP via STARTTLS (Auth Bypass)
CVE-2022-23532HIGH7.1same vendor
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and fu...
CVE-2022-37423HIGH7.5same vendor
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to ...