Skip to content

Commit d6e3159

Browse files
committed
update release notes
1 parent c818d4d commit d6e3159

File tree

1 file changed

+2
-0
lines changed

1 file changed

+2
-0
lines changed

release-notes/VERSION-2.x

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,8 @@ Project: jackson-databind
66

77
2.9.10.7 (not yet released)
88

9+
#2589: `DOMDeserializer`: setExpandEntityReferences(false) may not prevent
10+
external entity expansion in all cases [CVE-2020-25649]
911
#2854: Block one more gadget type (javax.swing, CVE-2020-xxx)
1012
(reported by Yangkun(ICSL))
1113

0 commit comments

Comments
 (0)