CVE-2021-42767: Path Traversal
A directory traversal vulnerability in the apoc plugins in Neo4J Graph database before 4.4.0.1 allows attackers to read local files, and sometimes create local files. This is fixed in 3.5.17, 4.2.10, 4.3.0.4, and 4.4.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42767?
CVE-2021-42767 is classified as a high-severity vulnerability due to its potential to allow attackers to read and create local files.
How do I fix CVE-2021-42767?
To resolve CVE-2021-42767, upgrade to Neo4j versions 3.5.17, 4.2.10, 4.3.0.4, or 4.4.0.1 or later.
What products are affected by CVE-2021-42767?
CVE-2021-42767 affects the Neo4j Awesome Procedures on Cypher versions prior to 3.5.17 and between 4.0.0 and 4.4.0.1.
What type of vulnerability is CVE-2021-42767?
CVE-2021-42767 is a directory traversal vulnerability, allowing unauthorized access to local files.
What is the impact of CVE-2021-42767?
The impact of CVE-2021-42767 includes unauthorized file reading and potentially unauthorized file creation on the server.