Description
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.
Remediation
References
https://github.com/neo4j-contrib/neo4j-apoc-procedures/security/advisories/GHSA-78f9-745f-278p
https://neo4j.com/docs/aura/platform/apoc/
Related Vulnerabilities
CVE-2020-35491 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-21391 Vulnerability in npm package @ckeditor/ckeditor5-media-embed
CVE-2020-17519 Vulnerability in maven package org.apache.flink:flink-runtime_2.12
CVE-2021-23594 Vulnerability in npm package realms-shim
CVE-2021-21430 Vulnerability in maven package org.openapitools:openapi-generator-project