Description
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c.
Remediation
References
https://0dd.zone/2018/10/27/neo4f-apoc-procedures-XXE/
https://github.com/neo4j-contrib/neo4j-apoc-procedures/issues/931
Related Vulnerabilities
CVE-2020-7623 Vulnerability in npm package jscover
CVE-2023-47324 Vulnerability in maven package org.silverpeas.core:silverpeas-core-war
CVE-2022-24897 Vulnerability in maven package org.xwiki.commons:xwiki-commons-velocity
CVE-2017-16218 Vulnerability in npm package dgard8.lab6
CVE-2020-35202 Vulnerability in maven package org.igniterealtime.openfire.plugins:dbaccess