Vulnerabilities (CVE)

Filtered by vendor Neo4j
Filtered by product Awesome Procedures On Cyper
Angry Yack Logo
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-23926 1 Neo4j 1 Awesome Procedures On Cyper 2024-11-21 N/A 5.9 MEDIUM
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml procedure of APOC core plugin prior to version 5.5.0 and 4.4.0.14 (4.4 branch) in Neo4j graph database. XML External Entity (XXE) injection occurs when the XML parser allows external entities to be resolved. The XML parser used by the apoc.import.graphml procedure was not configured in a secure way and therefore allowed this. External entities can be use ...

Show More

CVE-2022-23532 1 Neo4j 1 Awesome Procedures On Cyper 2024-11-21 N/A 7.1 HIGH
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j that provides hundreds of procedures and functions. A path traversal vulnerability found in the apoc.export.* procedures of apoc plugins in Neo4j Graph database. The issue allows a malicious actor to potentially break out of the expected directory. The vulnerability is such that files could only be created but not overwritten. For the vulnerability to be exploited, an attacker would need access to execute an arbitrary query, eith ...

Show More

CVE-2018-1000820 1 Neo4j 1 Awesome Procedures On Cyper 2024-11-21 7.5 HIGH 10.0 CRITICAL
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.