Skip to content

Commit 470fae8

Browse files
authored
Fixed SQL Injection Vulnerabilities (#1184) (#1185)
Fixed API `/taier/api/console/listNames` SQL Injection Vulnerabilities (#1184)
1 parent 4af3e15 commit 470fae8

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

taier-dao/src/main/resources/sqlmap/ScheduleJobCacheMapper.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -21,7 +21,7 @@
2121
<select id="listNames" resultType="java.lang.String">
2222
select job_name
2323
from schedule_job_cache
24-
where job_name like '%${jobName}%'
24+
where job_name like concat('%', #{jobName}, '%')
2525
and is_deleted = 0;
2626
</select>
2727

0 commit comments

Comments
 (0)