Skip to content

Commit 1fef25c

Browse files
committed
update release notes with cve ids
1 parent 27db111 commit 1fef25c

File tree

1 file changed

+5
-5
lines changed

1 file changed

+5
-5
lines changed

release-notes/VERSION-2.x

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -8,17 +8,17 @@ Project: jackson-databind
88

99
#2986: Block two more gadget types (commons-dbcp2, CVE-2020-35490/CVE-2020-35491)
1010
(reported by Al1ex@knownsec)
11-
#2996: Block 2 more gadget types (newrelic-agent)
11+
#2996: Block 2 more gadget types (newrelic-agent, CVE-2020-36188/CVE-2020-36189)
1212
(reported by Al1ex@knownsec)
13-
#2997: Block 2 more gadget types (tomcat/naming-factory-dbcp)
13+
#2997: Block 2 more gadget types (tomcat/naming-factory-dbcp, CVE-2020-36186/CVE-2020-36187)
1414
(reported by Al1ex@knownsec)
15-
#2998: Block 2 more gadget types (org.apache.tomcat/tomcat-dbcp)
15+
#2998: Block 2 more gadget types (org.apache.tomcat/tomcat-dbcp, CVE-2020-36184/CVE-2020-36185)
1616
(reported by Al1ex@knownsec)
1717
#2999: Block 1 more gadget type (org.glassfish.web/javax.servlet.jsp.jstl, CVE-2020-35728)
1818
(reported by bu5yer of Sangfor FarSight Security Lab)
19-
#3003: Block one more gadget type (xxx, CVE to be allocated)
19+
#3003: Block one more gadget type (org.docx4j.org.apache:xalan-interpretive, CVE-2020-36183)
2020
(reported by differ (of Zorelworld iLab team))
21-
#3004: Block one more DBCP-related potential gadget class
21+
#3004: Block some more DBCP-related potential gadget classes (CVE-2020-36179 - CVE-2020-36182)
2222
(reported by Al1ex@knownsec)
2323

2424
2.9.10.7 (02-Dec-2020)

0 commit comments

Comments
 (0)