PT-2022-23988 · Neo4J · Neo4J Apoc
Jonathan Leitschuh
·
Published
2022-08-12
·
Updated
2022-08-16
·
CVE-2022-37423
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Neo4j APOC versions 4.3.0.0 through 4.3.0.6
Neo4j APOC versions 4.4.0.0 through 4.4.0.7
Description
A Directory Traversal issue exists, allowing access to sibling directories via the
apoc.log.stream function. This issue is limited to sibling directories. For example, if a user-controlled path starts with "/usr/out", an attacker could access a directory named "/usr/outnot".Recommendations
For Neo4j APOC versions 4.3.0.0 through 4.3.0.6, update to version 4.3.0.7.
For Neo4j APOC versions 4.4.0.0 through 4.4.0.7, update to version 4.4.0.8.
As a temporary workaround, consider controlling the allowlist of functions that can be used in your system by configuring the
dbms.security.procedures.allowlist setting.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Neo4J Apoc