Skip to content

Commit 8fea3fc

Browse files
committed
Merge branch '2.8' into 2.9
2 parents 06a67f7 + 7a5f3f9 commit 8fea3fc

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

release-notes/VERSION-2.x

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -456,7 +456,7 @@ Project: jackson-databind
456456
(reported by henryptung@github)
457457
#1807: Jackson-databind caches plain map deserializer and use it even map has `@JsonDeserializer`
458458
(reported by lexas2509@github)
459-
#1855: Blacklist for more serialization gadgets (dbcp/tomcat, spring)
459+
#1855: Blacklist for more serialization gadgets (dbcp/tomcat, spring / CVE-2017-17485)
460460

461461
2.8.10 (24-Aug-2017)
462462

@@ -472,7 +472,7 @@ Project: jackson-databind
472472
binary formats (CBOR, Smile)
473473
#1735: Missing type checks when using polymorphic type ids
474474
(reported by Lukas Euler)
475-
#1737: Block more JDK types from polymorphic deserialization
475+
#1737: Block more JDK types from polymorphic deserialization (CVE 2017-15095)
476476

477477
2.8.9 (12-Jun-2017)
478478

0 commit comments

Comments
 (0)