A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0817 | A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1. |
Github GHSA |
GHSA-4mpj-488r-vh6m | Neo4j Graph Database vulnerable to Path Traversal |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:38:50.159Z
Reserved: 2021-10-20T00:00:00
Link: CVE-2021-42767
No data.
Status : Modified
Published: 2022-03-01T02:15:07.370
Modified: 2024-11-21T06:28:08.100
Link: CVE-2021-42767
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA