CVE-2021-43608

Source
https://nvd.nist.gov/vuln/detail/CVE-2021-43608
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43608.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2021-43608
Aliases
Related
Published
2021-12-09T20:15:07Z
Modified
2024-08-01T08:54:56.460675Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Doctrine DBAL 3.x before 3.1.4 allows SQL Injection. The escaping of offset and length inputs to the generation of a LIMIT clause was not probably cast to an integer, allowing SQL injection to take place if application developers passed unescaped user input to the DBAL QueryBuilder or any other API that ultimately uses the AbstractPlatform::modifyLimitQuery API.

References

Affected packages

Git / github.com/doctrine/dbal

Affected ranges

Type
GIT
Repo
https://github.com/doctrine/dbal
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

2.*

2.0-standalone-init
2.0.0
2.0.0-BETA1
2.0.0-BETA2
2.0.0-BETA3
2.0.0-BETA4
2.0.0-RC1
2.0.0RC2
2.0.0RC3
2.0.0RC4
2.0.0RC5
2.1.0
2.1.0RC1
2.1.0RC2
2.10.2
2.10.3
2.11.0
2.11.1
2.11.2
2.11.3
2.12.0
2.12.1
2.13.0
2.13.1
2.13.2
2.13.3
2.13.4
2.2.0-BETA2
2.2.0-beta1
2.3.0-BETA1
2.4.0-BETA1
2.4.0-BETA2
2.4.0-RC1
2.4.0-RC2

3.*

3.0.0
3.1.0
3.1.1
3.1.2
3.1.3

v2.*

v2.10.0
v2.10.1
v2.5.0-BETA2
v2.5.0-BETA3
v2.6.0
v2.7.0