Vulnerability Description
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Neo4J | Awesome Procedures On Cypher | < 4.3.0.7 |
Related Weaknesses (CWE)
References
- https://github.com/neo4j-contrib/neo4j-apoc-procedures/security/advisories/GHSA-ExploitThird Party Advisory
- https://neo4j.com/docs/aura/platform/apoc/ProductVendor Advisory
- https://github.com/neo4j-contrib/neo4j-apoc-procedures/security/advisories/GHSA-ExploitThird Party Advisory
- https://neo4j.com/docs/aura/platform/apoc/ProductVendor Advisory
FAQ
What is CVE-2022-37423?
CVE-2022-37423 is a vulnerability with a CVSS score of 7.5 (HIGH). Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.
How severe is CVE-2022-37423?
CVE-2022-37423 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-37423?
Check the references section above for vendor advisories and patch information. Affected products include: Neo4J Awesome Procedures On Cypher.