Skip to content

Commit

Permalink
MNSTR-5023 backport security fix from jackson2 - 2 more gadgets from …
Browse files Browse the repository at this point in the history
…(apache-drill, CVE-2020-14060)

Merged from FasterXML/jackson-databind#2688
  • Loading branch information
tkanafa-atlassian committed Apr 20, 2021
1 parent f2d0a7c commit 9d9be96
Showing 1 changed file with 2 additions and 0 deletions.
Expand Up @@ -177,6 +177,8 @@ public class SubTypeValidator

// [databind#2688]: apache/drill
s.add("oadd.org.apache.xalan.lib.sql.JNDIConnectionPool");
s.add("oadd.org.apache.commons.dbcp.datasources.PerUserPoolDataSource");
s.add("oadd.org.apache.commons.dbcp.datasources.SharedPoolDataSource");

// [databind#2698]: weblogic w/ oracle/aq-jms
// (note: dependency not available via Maven Central, but as part of
Expand Down

0 comments on commit 9d9be96

Please sign in to comment.