GHSA-r2pp-x4mm-4999

Suggest an improvement
Source
https://github.com/advisories/GHSA-r2pp-x4mm-4999
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-r2pp-x4mm-4999/GHSA-r2pp-x4mm-4999.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r2pp-x4mm-4999
Aliases
  • CVE-2018-1000820
Published
2018-12-20T22:02:02Z
Modified
2024-02-16T08:04:11.271299Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
XML External Entity (XXE) vulnerability in neo4j.procedure:apoc
Details

neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.

Database specific
{
    "cwe_ids": [
        "CWE-611"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-06-16T21:53:21Z",
    "nvd_published_at": "2018-12-20T15:29:00Z",
    "severity": "CRITICAL"
}
References

Affected packages

Maven / org.neo4j.procedure:apoc

Package

Name
org.neo4j.procedure:apoc
View open source insights on deps.dev
Purl
pkg:maven/org.neo4j.procedure/apoc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.4.0.4

Affected versions

1.*
1.0.0-RC1
1.0.0
1.1.0
3.*
3.0.4.1
3.0.4.2
3.0.8.4
3.0.8.5
3.1.0.2
3.1.0.3
3.1.0.4
3.1.0.5
3.1.2.5
3.1.3.7
3.1.3.8
3.1.3.9
3.2.0.1
3.2.0.4
3.2.3.5
3.2.3.6
3.3.0.1
3.3.0.2
3.3.0.3
3.3.0.4
3.4.0.1
3.4.0.2
3.4.0.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-r2pp-x4mm-4999/GHSA-r2pp-x4mm-4999.json"
last_known_affected_version_range
"<= 3.4.0.3"