Browse Source

Merge pull request #251 in CORE/base-third from ~ZED/base-third:release/10.0 to release/10.0

* commit '1e321d06edb66a6ccbb631a2d31de92ef6e40ec8':
  DEC-8889 jackson高危漏洞
release/10.0
zed 5 years ago
parent
commit
f4f4f517e9
  1. 10
      fine-jackson/src/com/fr/third/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java

10
fine-jackson/src/com/fr/third/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java

@ -78,6 +78,16 @@ public class SubTypeValidator
s.add("org.apache.openjpa.ee.RegistryManagedRuntime"); s.add("org.apache.openjpa.ee.RegistryManagedRuntime");
s.add("org.apache.openjpa.ee.JNDIManagedRuntime"); s.add("org.apache.openjpa.ee.JNDIManagedRuntime");
s.add("org.apache.axis2.transport.jms.JMSOutTransportInfo"); s.add("org.apache.axis2.transport.jms.JMSOutTransportInfo");
// [databind#2326] (2.9.9)
s.add("com.mysql.cj.jdbc.admin.MiniAdmin");
// [databind#2334]: logback-core (2.9.9.1)
s.add("ch.qos.logback.core.db.DriverManagerConnectionSource");
// [databind#2341]: jdom/jdom2 (2.9.9.1)
s.add("org.jdom.transform.XSLTransformer");
s.add("org.jdom2.transform.XSLTransformer");
DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s); DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
} }

Loading…
Cancel
Save