The identifier quoting in Doctrine DBAL has a potential security problem when user-input is passed into this function, making the security aspect of this functionality obsolete. If you make use of AbstractPlatform::quoteIdentifier() or Doctrine::quoteIdentifier() please upgrade immediately. The ORM itself does not use identifier quoting in combination with user-input, however we still urge everyone to update to the latest version of DBAL.
{
"cwe_ids": [],
"github_reviewed": true,
"github_reviewed_at": "2024-05-15T18:42:20Z",
"nvd_published_at": null,
"severity": "HIGH"
}