CRITICAL🇵🇱 Wersja polska

CVE-2021-42767

CVSS 9.1v3.1pub. 2022-03-01upd. 2024-11-21

A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Neo4j Awesome Procedures

    APP
    Neo4J
    < 3.5.0.174.2.0.0 – 4.2.10 (excl.)4.3.0.0 – 4.3.0.4 (excl.)4.4.0.0 – 4.4.0.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2021-34371CRITICAL9.8PL ✓same vendor

RCE przez deserializację RMI w Neo4j (shell server)

CVE-2018-1000820CRITICAL10.0PL ✓same vendor

XXE w Neo4j APOC Procedures — ujawnienie danych, SSRF, DoS

CVE-2018-18389CRITICAL9.8PL ✓same vendor

Neo4j Enterprise: ominięcie uwierzytelnienia LDAP via STARTTLS (Auth Bypass)

CVE-2022-23532HIGH7.1same vendor

APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and fu...

CVE-2022-37423HIGH7.5same vendor

Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to ...