We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent c818d4d commit d6e3159Copy full SHA for d6e3159
release-notes/VERSION-2.x
@@ -6,6 +6,8 @@ Project: jackson-databind
6
7
2.9.10.7 (not yet released)
8
9
+#2589: `DOMDeserializer`: setExpandEntityReferences(false) may not prevent
10
+ external entity expansion in all cases [CVE-2020-25649]
11
#2854: Block one more gadget type (javax.swing, CVE-2020-xxx)
12
(reported by Yangkun(ICSL))
13
0 commit comments