Description
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.
Remediation
References
https://github.com/neo4j-contrib/neo4j-apoc-procedures/security/advisories/GHSA-4mpj-488r-vh6m
https://neo4j.com
Related Vulnerabilities
CVE-2020-11994 Vulnerability in maven package org.apache.camel:camel-robotframework
CVE-2020-28472 Vulnerability in maven package org.webjars.bower:aws-sdk
CVE-2022-23106 Vulnerability in maven package io.jenkins:configuration-as-code
CVE-2017-3201 Vulnerability in maven package com.exadel.flamingo.flex:amf-serializer