Description
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.
Remediation
References
https://0dd.zone/2018/10/27/neo4f-apoc-procedures-XXE/
https://github.com/neo4j-contrib/neo4j-apoc-procedures/issues/931
Related Vulnerabilities
CVE-2022-1471 Vulnerability in maven package org.yaml:snakeyaml
CVE-2020-28438 Vulnerability in npm package deferred-exec
CVE-2022-24913 Vulnerability in maven package com.fasterxml.util:java-merge-sort
CVE-2018-1000632 Vulnerability in maven package org.jenkins-ci.dom4j:dom4j
CVE-2020-8441 Vulnerability in maven package org.jyaml:jyaml