CVE-2018-1000820
Summary
| CVE | CVE-2018-1000820 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-20 15:29:00 UTC |
| Updated | 2023-01-23 15:40:00 UTC |
| Description | neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This vulnerability appears to have been fixed in after commit 45bc09c. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Neo4j Apoc Procedures XXE | 0dd - The Zero (0) Day Division |
MISC |
0dd.zone |
Third Party Advisory |
| XXE in Xml.java · Issue #931 · neo4j-contrib/neo4j-apoc-procedures · GitHub |
MISC |
github.com |
Issue Tracking, Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 982319 Java (maven) Security Update for org.neo4j.procedure:apoc (GHSA-r2pp-x4mm-4999)