jackson-databind/CVE-2019-17267.patch
2020-09-20 00:02:00 +08:00

28 lines
1.2 KiB
Diff

From 191a4cdf87b56d2ddddb77edd895ee756b7f75eb Mon Sep 17 00:00:00 2001
From: Tatu Saloranta <tatu.saloranta@iki.fi>
Date: Thu, 19 Sep 2019 21:45:58 -0700
Subject: [PATCH] Fix #2460
---
.../jackson/databind/jsontype/impl/SubTypeValidator.java | 3 ++-
1 files changed, 2 insertions(+), 1 deletion(-)
diff --git a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
index 31f070ce5..594bb2029 100644
--- a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
+++ b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
@@ -90,8 +90,9 @@ public class SubTypeValidator
s.add("org.jdom.transform.XSLTransformer");
s.add("org.jdom2.transform.XSLTransformer");
- // [databind#2387]: EHCache
+ // [databind#2387], [databind#2460]: EHCache
s.add("net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup");
+ s.add("net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup");
// [databind#2389]: logback/jndi
s.add("ch.qos.logback.core.db.JNDIConnectionSource");
--
2.23.0