Skip to content

Commit e588f0a

Browse files
committed
Add ref from #2589 to CVE-2020-25649 in release notes for 2.11.0
1 parent 8b75ed4 commit e588f0a

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

release-notes/VERSION-2.x

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -96,7 +96,7 @@ Project: jackson-databind
9696
#2587: Add `MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES` to allow blocking
9797
use of unsafe base type for polymorphic deserialization
9898
#2589: `DOMDeserializer`: setExpandEntityReferences(false) may not prevent
99-
external entity expansion in all cases
99+
external entity expansion in all cases [CVE-2020-25649]
100100
(reported by Bartosz B)
101101
#2592: `ObjectMapper.setSerializationInclusion()` is ignored for `JsonAnyGetter`
102102
(reported by Oleksii K)

0 commit comments

Comments
 (0)