We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 840eae2 commit f6d9c66Copy full SHA for f6d9c66
release-notes/VERSION-2.x
@@ -12,6 +12,8 @@ Project: jackson-databind
12
(reported by Fangrun Li)
13
#2704: Block one more gadget type (weblogic/oracle-aqjms)
14
(reported by XuYuanzhen)
15
+#2765: Block one more gadget type (org.jsecurity))
16
+ (reported by Al1ex@knownsec)
17
18
2.9.10.4 (11-Apr-2020)
19
src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
@@ -194,6 +194,9 @@ public class SubTypeValidator
194
s.add("oracle.jms.AQjmsXAQueueConnectionFactory");
195
s.add("oracle.jms.AQjmsXAConnectionFactory");
196
197
+ // [databind#2764]: org.jsecurity:
198
+ s.add("org.jsecurity.realm.jndi.JndiRealmFactory");
199
+
200
DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
201
}
202
0 commit comments