Uploaded image for project: 'TinkerPop'
  1. TinkerPop
  2. TINKERPOP-2880

Deserialization of Untrusted Data in Neo4j

    XMLWordPrintableJSON

Details

    • Improvement
    • Status: Closed
    • Major
    • Resolution: Not A Bug
    • 3.6.2
    • None
    • neo4j
    • Patch, Important

    Description

      Vulnerability in neo4j-3.4.11.

      Need to update to 3.5 or higher.

      https://github.com/advisories/GHSA-pc4w-8v5j-29w9

       

      Package path...

      • /opt/gremlin-server/ext/neo4j-gremlin/lib/neo4j-3.4.11.jar
      • /opt/gremlin-server/ext/neo4j-gremlin/plugin/neo4j-3.4.11.jar
      • /root/.groovy/grapes/org.neo4j/neo4j/jars/neo4j-3.4.11.jar

      Attachments

        Issue Links

          Activity

            People

              Unassigned Unassigned
              jfoscue Jim Foscue
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: