{"id":"GHSA-78f9-745f-278p","summary":"Neo4j Graph apoc plugins Partial Path Traversal Vulnerability","details":"### Impact\nA partial Directory Traversal Vulnerability found in `apoc.log.stream` function of apoc plugins in Neo4j Graph database. \nThis issue allows a malicious actor to potentially break out of the expected directory. The impact is limited to sibling directories. For example, `userControlled.getCanonicalPath().startsWith(\"/usr/out\")` will allow an attacker to access a directory with a name like `/usr/outnot`.\n\n### Patches\nThe users should aim to use the latest released version compatible with their Neo4j version. The minimum versions containing patch for this vulnerability are 4.4.0.8 and 4.3.0.7\n\n### Workarounds\nIf you cannot upgrade the library, you can control the [allowlist of the functions](https://neo4j.com/docs/operations-manual/current/reference/configuration-settings/#config_dbms.security.procedures.allowlist) that can be used in your system\n\n\n### For more information\nIf you have any questions or comments about this advisory:\n- Open an issue in [neo4j-apoc-procedures](https://github.com/neo4j-contrib/neo4j-apoc-procedures)\n- Email us at [security@neo4j.com](mailto:security@neo4j.com)\n\n### Credits\nWe want to publicly recognise the contribution of [Jonathan Leitschuh](https://github.com/JLLeitschuh) for reporting this issue.\n ","aliases":["CVE-2022-37423"],"modified":"2026-07-08T06:30:01.641702143Z","published":"2022-08-12T15:38:33Z","database_specific":{"nvd_published_at":"2022-08-12T15:15:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-08-12T15:38:33Z"},"references":[{"type":"WEB","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/security/advisories/GHSA-78f9-745f-278p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37423"},{"type":"WEB","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/pull/3080"},{"type":"WEB","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/commit/d2f415c6f703bbc2cda4a753928821ff15d5c620"},{"type":"WEB","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/commit/fe9f8c77269f5a742585c1d62324eb70755de510"},{"type":"PACKAGE","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures"},{"type":"WEB","url":"https://neo4j.com/docs/aura/platform/apoc"}],"affected":[{"package":{"name":"org.neo4j.procedure:apoc","ecosystem":"Maven","purl":"pkg:maven/org.neo4j.procedure/apoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.4.0.0"},{"fixed":"4.4.0.8"}]}],"versions":["4.4.0.0","4.4.0.1","4.4.0.2","4.4.0.3","4.4.0.4","4.4.0.5","4.4.0.6","4.4.0.7"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-78f9-745f-278p/GHSA-78f9-745f-278p.json"}},{"package":{"name":"org.neo4j.procedure:apoc","ecosystem":"Maven","purl":"pkg:maven/org.neo4j.procedure/apoc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0.7"}]}],"versions":["1.0.0","1.0.0-RC1","1.1.0","3.0.4.1","3.0.4.2","3.0.8.4","3.0.8.5","3.1.0.2","3.1.0.3","3.1.0.4","3.1.0.5","3.1.2.5","3.1.3.7","3.1.3.8","3.1.3.9","3.2.0.1","3.2.0.4","3.2.3.5","3.2.3.6","3.3.0.1","3.3.0.2","3.3.0.3","3.3.0.4","3.4.0.1","3.4.0.2","3.4.0.3","3.4.0.4","3.4.0.5","3.4.0.7","3.5.0.1","3.5.0.10","3.5.0.11","3.5.0.12","3.5.0.13","3.5.0.14","3.5.0.15","3.5.0.17","3.5.0.18","3.5.0.19","3.5.0.2","3.5.0.20","3.5.0.21","3.5.0.4","3.5.0.5","3.5.0.6","3.5.0.7","4.0.0-rc01","4.0.0.0","4.0.0.1","4.0.0.10","4.0.0.11","4.0.0.12","4.0.0.13","4.0.0.14","4.0.0.15","4.0.0.16","4.0.0.17","4.0.0.18","4.0.0.2","4.0.0.5","4.0.0.6","4.0.0.7","4.0.0.8","4.0.0.9","4.1.0.0","4.1.0.1","4.1.0.10","4.1.0.11","4.1.0.12","4.1.0.2","4.1.0.3","4.1.0.4","4.1.0.5","4.1.0.6","4.1.0.7","4.1.0.8","4.1.0.9","4.2.0.0","4.2.0.1","4.2.0.10","4.2.0.11","4.2.0.12","4.2.0.2","4.2.0.3","4.2.0.4","4.2.0.5","4.2.0.6","4.2.0.7","4.2.0.8","4.2.0.9","4.3.0.0","4.3.0.1","4.3.0.2","4.3.0.3","4.3.0.4","4.3.0.5","4.3.0.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/08/GHSA-78f9-745f-278p/GHSA-78f9-745f-278p.json"}}],"schema_version":"1.9.0"}