File tree 2 files changed +14
-0
lines changed
src/main/java/com/fasterxml/jackson/databind/jsontype/impl
2 files changed +14
-0
lines changed Original file line number Diff line number Diff line change @@ -4,6 +4,13 @@ Project: jackson-databind
4
4
=== Releases ===
5
5
------------------------------------------------------------------------
6
6
7
+ 2.9.10.4 (not yet released)
8
+
9
+ #2631 : Block one more gadget type (shaded-hikari-config, CVE-to-be-allocated)
10
+ (reported by threedr3am & LFY)
11
+ #2634 : Block two more gadget types (ibatis-sqlmap, anteros-core; CVE-to-be-allocated)
12
+ (reported by threedr3am & V1ZkRA)
13
+
7
14
2.9.10.3 (23 -Feb-2020 )
8
15
9
16
#2620 : Block one more gadget type (xbean-reflect/JNDI - CVE-2020 -8840 )
Original file line number Diff line number Diff line change @@ -128,6 +128,13 @@ public class SubTypeValidator
128
128
// [databind#2620]: xbean-reflect
129
129
s .add ("org.apache.xbean.propertyeditor.JndiConverter" );
130
130
131
+ // [databind#2631]: shaded hikari-config
132
+ s .add ("org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig" );
133
+
134
+ // [databind#2634]: ibatis-sqlmap, anteros-core
135
+ s .add ("com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig" );
136
+ s .add ("br.com.anteros.dbcp.AnterosDBCPConfig" );
137
+
131
138
DEFAULT_NO_DESER_CLASS_NAMES = Collections .unmodifiableSet (s );
132
139
}
133
140
You can’t perform that action at this time.
0 commit comments