PT-2024-40149 · Doctrine · Doctrine Dbal

Published

2024-05-15

·

Updated

2024-05-15

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Doctrine DBAL (affected versions not specified)
Description: The identifier quoting in Doctrine DBAL has a potential security issue when user-input is passed into the quoting function, rendering the security aspect of this functionality obsolete.
Recommendations: Upgrade to the latest version of DBAL to resolve the issue. As a temporary workaround, consider avoiding the use of user-input in the quoteIdentifier() function until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

GHSA-76W8-MQX4-WJRF

Affected Products

Doctrine Dbal