VDB
Sign up
HIGH8.1

GHSA-76w8-mqx4-wjrf

Doctrine DBAL SQL injection possibility

Quick fix

GHSA-76w8-mqx4-wjrf — doctrine/dbal: upgrade to the fixed version with the command below.

composer require doctrine/dbal:^2.0.8

Details

The identifier quoting in Doctrine DBAL has a potential security problem when user-input is passed into this function, making the security aspect of this functionality obsolete. If you make use of AbstractPlatform::quoteIdentifier() or Doctrine::quoteIdentifier() please upgrade immediately. The ORM itself does not use identifier quoting in combination with user-input, however we still urge everyone to update to the latest version of DBAL.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/doctrine/dbal
Introduced in: 2.0.0Fixed in: 2.0.8
Fixcomposer require doctrine/dbal:^2.0.8
Packagist/doctrine/dbal
Introduced in: 2.1.0Fixed in: 2.1.2
Fixcomposer require doctrine/dbal:^2.1.2

References