{"id":"CVE-2022-37423","aliases":["GHSA-78f9-745f-278p"],"url":"https://o3.security/vulnerability/CVE-2022-37423","summary":"Neo4j Graph apoc plugins Partial Path Traversal Vulnerability","details":"### Impact\nA partial Directory Traversal Vulnerability found in `apoc.log.stream` function of apoc plugins in Neo4j Graph database. \nThis issue allows a malicious actor to potentially break out of the expected directory. The impact is limited to sibling directories. For example, `userControlled.getCanonicalPath().startsWith(\"/usr/out\")` will allow an attacker to access a directory with a name like `/usr/outnot`.\n\n### Patches\nThe users should aim to use the latest released version compatible with their Neo4j version. The minimum versions containing patch for this vulnerability are 4.4.0.8 and 4.3.0.7\n\n### Workarounds\nIf you cannot upgrade the library, you can control the [allowlist of the functions](https://neo4j.com/docs/operations-manual/current/reference/configuration-settings/#config_dbms.security.procedures.allowlist) that can be used in your system\n\n\n### For more information\nIf you have any questions or comments about this advisory:\n- Open an issue in [neo4j-apoc-procedures](https://github.com/neo4j-contrib/neo4j-apoc-procedures)\n- Email us at [security@neo4j.com](mailto:security@neo4j.com)\n\n### Credits\nWe want to publicly recognise the contribution of [Jonathan Leitschuh](https://github.com/JLLeitschuh) for reporting this issue.\n ","published":"2022-08-12T12:16:36Z","modified":"2026-08-12T13:33:07.777649Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Maven","name":"org.neo4j.procedure:apoc","fixedVersion":"4.4.0.8"},{"ecosystem":"Maven","name":"org.neo4j.procedure:apoc","fixedVersion":"4.3.0.7"}],"fix":{"url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/pull/3080","label":"neo4j-contrib/neo4j-apoc-procedures#3080"},"references":[{"type":"WEB","url":"https://neo4j.com/docs/aura/platform/apoc/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/37xxx/CVE-2022-37423.json"},{"type":"ADVISORY","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/security/advisories/GHSA-78f9-745f-278p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-37423"},{"type":"WEB","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/pull/3080"},{"type":"WEB","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/commit/d2f415c6f703bbc2cda4a753928821ff15d5c620"},{"type":"WEB","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures/commit/fe9f8c77269f5a742585c1d62324eb70755de510"},{"type":"PACKAGE","url":"https://github.com/neo4j-contrib/neo4j-apoc-procedures"},{"type":"WEB","url":"https://neo4j.com/docs/aura/platform/apoc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T13:33:07.777649Z"}}