jackson-databind/CVE-2019-14892.patch

30 lines
1.2 KiB
Diff
Raw Normal View History

2020-09-20 00:02:00 +08:00
From 41b7f9b90149e9d44a65a8261a8deedc7186f6af Mon Sep 17 00:00:00 2001
From: Tatu Saloranta <tatu.saloranta@iki.fi>
Date: Thu, 19 Sep 2019 22:57:18 -0700
Subject: [PATCH] Actual #2462 fix (prev commit only updates release notes)
---
.../jackson/databind/jsontype/impl/SubTypeValidator.java | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
index 594bb2029..8117f11ad 100644
--- a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
+++ b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
@@ -104,7 +104,11 @@ public class SubTypeValidator
// [databind#2420]: CXF/JAX-RS provider/XSLT
s.add("org.apache.cxf.jaxrs.provider.XSLTJaxbProvider");
-
+
+ // [databind#2462]: commons-configuration / -2
+ s.add("org.apache.commons.configuration.JNDIConfiguration");
+ s.add("org.apache.commons.configuration2.JNDIConfiguration");
+
DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
}
--
2.23.0