Directory Traversal Vulnerability in Neo4j APOC by Neo4j
CVE-2022-37423
7.5HIGH
What is CVE-2022-37423?
The Neo4j APOC library prior to versions 4.3.0.7 and 4.x before 4.4.0.8 contains a directory traversal vulnerability that permits unauthorized access to sibling directories through the apoc.log.stream procedure. This flaw can be exploited by attackers to potentially read sensitive files outside of the intended directory structure, posing a significant security risk.
