CVE-2021-43822 is a high-severity (CVSS 7.5) SQL Injection vulnerability in jackalope/jackalope-doctrine-dbal. A fix is available for jackalope/jackalope-doctrine-dbal — see the affected versions and patch details below.
SQL injection in jackalope/jackalope-doctrine-dbal
EPSS Exploitation Probability
Probability of exploitation in the next 30 days, from FIRST.org EPSS.
How urgent is this, really
CVE-2021-43822 by exploitation likelihood (EPSS) against impact (CVSS). Outside the shaded patch-first corner.
Where this sits among everything scored
Of 385,738 CVEs with a current EPSS score, this one falls in the < 10% band (highlighted). Counts from FIRST.org, log-scaled.
Real-World Exposure
jackalope/jackalope-doctrine-dbalReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects Packagist packages — download data is not available via public APIs for these ecosystems.
Description
Impact
Users can provoke SQL injections if they can specify a node name or query.
Patches
Upgrade to version 1.7.4
If that is not possible, you can escape all places where $property is used to filter sv:name in the class Jackalope\Transport\DoctrineDBAL\Query\QOMWalker: XPath::escape($property).
Workarounds
Node names and xpaths can contain " or ; according to the JCR specification. The jackalope component that translates the query object model into doctrine dbal queries does not properly escape the names and paths, so that a accordingly crafted node name can lead to an SQL injection.
If queries are never done from user input, or if you validate the user input to not contain ;, you are not affected.
References
No further references.
For more information
If you have any questions or comments about this advisory:
- Open an issue in jackalope/jackalope-doctrine-dbal repo
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🐘Packagist | jackalope/jackalope-doctrine-dbal | all versions | 1.7.4composer require jackalope/jackalope-doctrine-dbal:^1.7.4 |
Affected Products
jackalope doctrine-dbaljackalope_doctrine-dbal_projectDetection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for jackalope/jackalope-doctrine-dbal, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update jackalope/jackalope-doctrine-dbal to 1.7.4 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms CVE-2021-43822 is resolved across your whole dependency graph.
Workarounds
Until you can upgrade, make sure every query built from user input uses parameterised statements or a prepared-statement API rather than string concatenation, and reduce the database account's privileges so an injected query cannot read or alter data beyond what the feature needs.
Frequently Asked Questions
Is CVE-2021-43822 in your dependencies?
Find it across Packagist, including transitive dependencies.