{"id":"GHSA-r7cj-8hjg-x622","summary":"DBAL 3 SQL Injection Security Vulnerability","details":"We have released a new version Doctrine DBAL 3.1.4 that fixes a critical SQL injection vulnerability in the LIMIT clause generation API provided by the Platform abstraction.\n\nWe advise everyone using Doctrine DBAL 3.0.0 up to 3.1.3 to upgrade to 3.1.4 immediately.\n\nThe vulnerability can happen when unsanitized input is passed to many APIs in Doctrine DBAL and ORM that ultimately end up calling `AbstractPlatform::modifyLimitQuery`. \n\nAs a workaround you can cast all limit and offset parameters to integers before passing them to Doctrine APIs.\n\nThis vulnerability has been assigned [CVE-2021-43608](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-43608).\n","aliases":["CVE-2021-43608"],"modified":"2026-07-08T06:28:09.549082612Z","published":"2021-11-16T17:25:57Z","database_specific":{"nvd_published_at":"2021-12-09T20:15:00Z","cwe_ids":["CWE-89"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2021-11-15T22:34:32Z"},"references":[{"type":"WEB","url":"https://github.com/doctrine/dbal/security/advisories/GHSA-r7cj-8hjg-x622"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43608"},{"type":"WEB","url":"https://github.com/doctrine/dbal/commit/9dcfa4cb6c03250b78a84737ba7ceb82f4b7ba4d"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/doctrine/dbal/CVE-2021-43608.yaml"},{"type":"WEB","url":"https://github.com/doctrine/dbal"},{"type":"WEB","url":"https://github.com/doctrine/dbal/releases"},{"type":"WEB","url":"https://www.doctrine-project.org/2021/11/11/dbal3-vulnerability-fixed.html"}],"affected":[{"package":{"name":"doctrine/dbal","ecosystem":"Packagist","purl":"pkg:composer/doctrine/dbal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.1.4"}]}],"versions":["3.0.0","3.1.0","3.1.1","3.1.2","3.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/11/GHSA-r7cj-8hjg-x622/GHSA-r7cj-8hjg-x622.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}