CVE-2021-42767

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
01/03/2022
Last modified:
04/10/2022

Description

A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:neo4j:awesome_procedures:*:*:*:*:*:neo4j:*:* 3.5.0.17 (excluding)
cpe:2.3:a:neo4j:awesome_procedures:*:*:*:*:*:neo4j:*:* 4.2.0.0 (including) 4.2.10 (excluding)
cpe:2.3:a:neo4j:awesome_procedures:*:*:*:*:*:neo4j:*:* 4.3.0.0 (including) 4.3.0.4 (excluding)
cpe:2.3:a:neo4j:awesome_procedures:*:*:*:*:*:neo4j:*:* 4.4.0.0 (including) 4.4.0.1 (excluding)