Directory Traversal Vulnerability in Neo4J Graph Database by Neo4J
CVE-2021-42767
9.1CRITICAL
What is CVE-2021-42767?
A directory traversal vulnerability exists in the apoc plugins of the Neo4J Graph database, allowing potential attackers to exploit the system. This flaw enables unauthorized access to local files, and in certain cases, may permit the creation of local files. The vulnerability impacts versions before 4.4.0.1 and can expose sensitive information or disrupt system operations if left unaddressed. Users are urged to upgrade to patched versions, including 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1, to safeguard their environments.
