CVE-2022-37423: Path Traversal
Published Aug 12, 2022
·Updated
Neo4j APOC (Awesome Procedures on Cypher) before 4.3.0.7 and 4.x before 4.4.0.8 allows Directory Traversal to sibling directories via apoc.log.stream.
Affected Software
2 affected components
Neo4j Awesome Procedures on Cypher<4.3.0.7
Neo4j Awesome Procedures on Cypher>=4.4.0.0<4.4.0.8
Event History
Aug 12, 2022
CVE Published
via MITRE·12:16 PM
Data Sourced
via MITRE·12:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-37423?
CVE-2022-37423 has been classified as a high severity vulnerability due to its potential for directory traversal attacks.
2
How do I fix CVE-2022-37423?
To resolve CVE-2022-37423, upgrade Neo4j APOC to version 4.3.0.7 or 4.4.0.8 or later.
3
What impact does CVE-2022-37423 have on my system?
CVE-2022-37423 allows unauthorized access to sibling directories, which can lead to information disclosure.
4
What versions are affected by CVE-2022-37423?
CVE-2022-37423 affects Neo4j APOC versions prior to 4.3.0.7 and from 4.4.0.0 to 4.4.0.8.
5
Is CVE-2022-37423 exploitable remotely?
Yes, CVE-2022-37423 can be potentially exploited remotely without authentication.