← Back

CVE-2021-42767

nvd nist
Published: Mar 1, 2022Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.

Affected (4)

1 product
Awesome Procedures
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Neo4j
Before 3.5.0.17
From 4.2.0.0 to 4.2.10
From 4.3.0.0 to 4.3.0.4
From 4.4.0.0 to 4.4.0.1

References (4)

Source: cve@mitre.org
ProductVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ProductVendor Advisory

Timeline

No history available yet.