Skip to content

Commit 3c95106

Browse files
committed
Backport 6 CVE fixes from 2.8 (now up to 2.9.10[.1] set, similar to 2.6.7.3)
1 parent 274ca77 commit 3c95106

File tree

2 files changed

+12
-3
lines changed

2 files changed

+12
-3
lines changed

release-notes/VERSION

+9
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,15 @@ Project: jackson-databind
44
=== Releases ===
55
------------------------------------------------------------------------
66

7+
2.7.9.7 (not yet released)
8+
9+
#2410: Block one more gadget type (HikariCP, CVE-2019-14540)
10+
#2420: Block one more gadget type (cxf-jax-rs, no CVE allocated yet)
11+
#2449: Block one more gadget type (HikariCP, CVE-2019-14439 / CVE-2019-16335)
12+
#2462: Block two more gadget types (commons-configuration/-2)
13+
#2478: Block two more gadget types (commons-dbcp, p6spy, CVE-2019-16942 / CVE-2019-16943)
14+
#2498: Block one more gadget type (apache-log4j-extras/1.2, CVE-2019-17531)
15+
716
2.7.9.6 (26-Jul-2019)
817

918
#2326: Block one more gadget type (CVE-2019-12086)

src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java

+3-3
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,9 @@ public class SubTypeValidator
5454
// [databind#1855]: more 3rd party
5555
s.add("org.apache.tomcat.dbcp.dbcp2.BasicDataSource");
5656
s.add("com.sun.org.apache.bcel.internal.util.ClassLoader");
57+
// [databind#1899]: more 3rd party
58+
s.add("org.hibernate.jmx.StatisticsService");
59+
s.add("org.apache.ibatis.datasource.jndi.JndiDataSourceFactory");
5760
// [databind#2032]: more 3rd party; data exfiltration via xml parsed ext entities
5861
s.add("org.apache.ibatis.parsing.XPathParser");
5962

@@ -63,9 +66,6 @@ public class SubTypeValidator
6366
// [databind#2058]: Oracle JDBC driver, with jndi/ldap lookup
6467
s.add("oracle.jdbc.connector.OracleManagedConnectionFactory");
6568
s.add("oracle.jdbc.rowset.OracleJDBCRowSet");
66-
// [databind#1899]: more 3rd party
67-
s.add("org.hibernate.jmx.StatisticsService");
68-
s.add("org.apache.ibatis.datasource.jndi.JndiDataSourceFactory");
6969

7070
// [databind#2097]: some 3rd party, one JDK-bundled
7171
s.add("org.slf4j.ext.EventData");

0 commit comments

Comments
 (0)