jackson-databind/CVE-2019-12814.patch
2020-09-20 00:02:00 +08:00

29 lines
1.2 KiB
Diff

From 5f7c69bba07a7155adde130d9dee2e54a54f1fa5 Mon Sep 17 00:00:00 2001
From: Tatu Saloranta <tatu.saloranta@iki.fi>
Date: Thu, 13 Jun 2019 20:24:03 -0700
Subject: [PATCH] Fix #2341
---
.../jackson/databind/jsontype/impl/SubTypeValidator.java | 8 ++++++--
1 files changed, 6 insertions(+), 2 deletions(-)
diff --git a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
index 102abb6e2..c4d7f3827 100644
--- a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
+++ b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
@@ -83,8 +83,13 @@ public class SubTypeValidator
// [databind#2326] (2.9.9)
s.add("com.mysql.cj.jdbc.admin.MiniAdmin");
- // [databind#2334] (2.9.9.1): logback-core
+ // [databind#2334] (2.9.9.1)
s.add("ch.qos.logback.core.db.DriverManagerConnectionSource");
+
+ // [databind#2341]: jdom/jdom2
+ s.add("org.jdom.transform.XSLTransformer");
+ s.add("org.jdom2.transform.XSLTransformer");
+
DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
}