Skip to content

Commit 1731fd7

Browse files
committed
Merge branch '2.9' into 2.10
2 parents c9f36d9 + 0b887a0 commit 1731fd7

File tree

2 files changed

+13
-0
lines changed

2 files changed

+13
-0
lines changed

release-notes/VERSION-2.x

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,13 @@ Project: jackson-databind
6969
#2339: Suboptimal return type for `ObjectNode.set()`
7070
(reported by Victor N)
7171

72+
2.9.10 (not yet released)
73+
74+
#2410: Block one more gadget type (CVE-2019-14540)
75+
(reported by iSafeBlue@github / [email protected])
76+
#2420: Block one more gadget type (no CVE allocated yet)
77+
(reported by [email protected])
78+
7279
2.9.9.3 (06-Aug-2019)
7380

7481
#2395: `NullPointerException` from `ResolvedRecursiveType` (regression due to fix for #2331)

src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -96,6 +96,12 @@ public class SubTypeValidator
9696
// [databind#2389]: logback/jndi
9797
s.add("ch.qos.logback.core.db.JNDIConnectionSource");
9898

99+
// [databind#2410]: HikariCP/metricRegistry config
100+
s.add("com.zaxxer.hikari.HikariConfig");
101+
102+
// [databind#2420]: CXF/JAX-RS provider/XSLT
103+
s.add("org.apache.cxf.jaxrs.provider.XSLTJaxbProvider");
104+
99105
DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
100106
}
101107

0 commit comments

Comments
 (0)