CVE-2011-1522: SQL Injection
Latest upstream release: 1.2.4 Current version in Fedora Rawhide: 1.2.3 URL: http://pear.doctrine-project.org/feed.xml
Please consult the package updates policy before you issue an update to a stable branch: https://fedoraproject.org/wiki/UpdatesPolicy
More information about the service that created this bug can be found at: https://fedoraproject.org/wiki/Upstreamreleasemonitoring
Other sources
Multiple SQL injection vulnerabilities in the Doctrine\DBAL\Platforms\AbstractPlatform::modifyLimitQuery function in Doctrine 1.x before 1.2.4 and 2.x before 2.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) limit or (2) offset field.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1522?
CVE-2011-1522 has a moderate severity level, which indicates it could lead to some impact but not critical issues.
How do I fix CVE-2011-1522?
To fix CVE-2011-1522, upgrade to version 1.2.4 or later of the Doctrine Object Relational Mapper.
Which versions of Doctrine are affected by CVE-2011-1522?
CVE-2011-1522 affects Doctrine versions 1.2.0 through 1.2.3 and 2.0.0 alpha, beta, and release candidate versions.
Is there a patch available for CVE-2011-1522?
Yes, the patch for CVE-2011-1522 is included in the updated version 1.2.4 of the Doctrine ORM.
What are the potential vulnerabilities of CVE-2011-1522?
The potential vulnerabilities of CVE-2011-1522 could lead to application integrity issues or data leakage under certain circumstances.