GHSA-78f9-745f-278p

    Dashboard / Vulnerabilities / GHSA-78f9-745f-278p

    GHSA-78f9-745f-278p

    Published: 12 Aug 2022Last Modified: 8 Jul 2026

    Summary: Neo4j Graph apoc plugins Partial Path Traversal Vulnerability

    Details: ### Impact A partial Directory Traversal Vulnerability found in `apoc.log.stream` function of apoc plugins in Neo4j Graph database. This issue allows a malicious actor to potentially break out of the expected directory. The impact is limited to sibling directories. For example, `userControlled.getCanonicalPath().startsWith("/usr/out")` will allow an attacker to access a directory with a name like `/usr/outnot`. ### Patches The users should aim to use the latest released version compatible with their Neo4j version. The minimum versions containing patch for this vulnerability are 4.4.0.8 and 4.3.0.7 ### Workarounds If you cannot upgrade the library, you can control the [allowlist of the functions](https://neo4j.com/docs/operations-manual/current/reference/configuration-settings/#config_dbms.security.procedures.allowlist) that can be used in your system ### For more information If you have any questions or comments about this advisory: - Open an issue in [neo4j-apoc-procedures](https://github.com/neo4j-contrib/neo4j-apoc-procedures) - Email us at [[email protected]](mailto:[email protected]) ### Credits We want to publicly recognise the contribution of [Jonathan Leitschuh](https://github.com/JLLeitschuh) for reporting this issue.

    Affected packages

    Package

    Name: org.neo4j.procedure:apoc

    Purl: pkg:maven/org.neo4j.procedure/apoc

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 4.4.0.0
    Fixed -4.4.0.8

    Affected versions

    4.4.0.0
    4.4.0.1
    4.4.0.2
    4.4.0.3
    4.4.0.4
    4.4.0.5
    4.4.0.6
    4.4.0.7

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-78f9-745f-278p | CVE-DB