Skip to content

Commit 98c42f7

Browse files
Block two more gadget types (commons-configuration/-2)
Merged from FasterXML/jackson-databind#2462
1 parent 80ecfc4 commit 98c42f7

File tree

2 files changed

+6
-0
lines changed

2 files changed

+6
-0
lines changed

release-notes/VERSION

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -64,6 +64,7 @@ One more patch release for 1.9.
6464
* [databind#2682]: Block one more gadget type (commons-jelly, CVE-2020-11620)
6565
* [databind#2688]: Block one more gadget type (apache-drill)
6666
* [databind#2698]: Block one more gadget type (weblogic/oracle-aqjms)
67+
* [databind#2462]: Block two more gadget types (commons-configuration/-2)
6768

6869
1.9.13 (14-Jul-2013)
6970

src/mapper/java/org/codehaus/jackson/map/jsontype/impl/SubTypeValidator.java

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,6 +99,11 @@ public class SubTypeValidator
9999
s.add("com.zaxxer.hikari.HikariDataSource");
100100
// [databind#2420]: CXF/JAX-RS provider/XSLT
101101
s.add("org.apache.cxf.jaxrs.provider.XSLTJaxbProvider");
102+
103+
// [databind#2462]: commons-configuration / -2
104+
s.add("org.apache.commons.configuration.JNDIConfiguration");
105+
s.add("org.apache.commons.configuration2.JNDIConfiguration");
106+
102107
// [databind#2478]: comons-dbcp, p6spy
103108
s.add("org.apache.commons.dbcp.datasources.SharedPoolDataSource");
104109
s.add("com.p6spy.engine.spy.P6DataSource");

0 commit comments

Comments
 (0)