Skip to content

Commit b1d70fc

Browse files
committed
MAGETWO-42038: RCE/DOS via cron.php
- Changes based on code review feedback.
1 parent 2740882 commit b1d70fc

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

app/code/Magento/Cron/Observer/ProcessCronQueueObserver.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -149,7 +149,7 @@ public function execute(\Magento\Framework\Event\Observer $observer)
149149

150150
foreach ($jobGroupsRoot as $groupId => $jobsRoot) {
151151
if ($this->_request->getParam('group') !== null
152-
&& $this->_request->getParam('group') !== escapeshellarg($groupId)
152+
&& $this->_request->getParam('group') !== '\'' . ($groupId) . '\''
153153
&& $this->_request->getParam('group') !== $groupId) {
154154
continue;
155155
}

0 commit comments

Comments
 (0)