Skip to content

Commit 8d63c1b

Browse files
authored
fix(rce): prevent remot code execution (#833)
1 parent e31db68 commit 8d63c1b

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

lib/sidekiq_unique_jobs/web.rb

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -85,8 +85,9 @@ def self.registered(app) # rubocop:disable Metrics/MethodLength, Metrics/AbcSize
8585

8686
app.get "/locks/:digest/jobs/:job_id/delete" do
8787
@digest = h(params[:digest])
88+
@job_id = h(params[:job_id])
8889
@lock = SidekiqUniqueJobs::Lock.new(@digest)
89-
@lock.unlock(params[:job_id])
90+
@lock.unlock(@job_id)
9091

9192
redirect_to "locks/#{@lock.key}"
9293
end

0 commit comments

Comments
 (0)