We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent b596365 commit c9ef4a1Copy full SHA for c9ef4a1
release-notes/VERSION
@@ -8,6 +8,7 @@ Not yet released
8
9
#2326: Block class for CVE-2019-12086
10
(contributed by MaximilianTews@github)
11
+#2334: Block class for CVE-2019-12384
12
13
2.7.9.5 (23-Nov-2018)
14
src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
@@ -81,6 +81,9 @@ public class SubTypeValidator
81
82
// [databind#2326] (2.7.9.6): one more 3rd party gadget
83
s.add("com.mysql.cj.jdbc.admin.MiniAdmin");
84
+
85
+ // [databind#2334] (2.9.9.1): logback-core
86
+ s.add("ch.qos.logback.core.db.DriverManagerConnectionSource");
87
88
DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
89
}
0 commit comments