jackson-databind/CVE-2020-14062.patch
2020-09-20 00:02:00 +08:00

29 lines
1.3 KiB
Diff

From 840eae2ca81c597a0010b2126f32dce17d384b70 Mon Sep 17 00:00:00 2001
From: Tatu Saloranta <tatu.saloranta@iki.fi>
Date: Fri, 1 May 2020 19:19:10 -0700
Subject: [PATCH] ... actual #2704 fix here (forgot to commit change)
---
.../jackson/databind/jsontype/impl/SubTypeValidator.java | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
index 20bbf2059..80cc37879 100644
--- a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
+++ b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java
@@ -113,8 +113,10 @@ public class SubTypeValidator
s.add("org.apache.commons.configuration.JNDIConfiguration");
s.add("org.apache.commons.configuration2.JNDIConfiguration");
- // [databind#2469]: xalan2
+ // [databind#2469]: xalan
s.add("org.apache.xalan.lib.sql.JNDIConnectionPool");
+ // [databind#2704]: xalan2
+ s.add("com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool");
// [databind#2478]: comons-dbcp, p6spy
s.add("org.apache.commons.dbcp.datasources.PerUserPoolDataSource");
--
2.23.0