Skip to content

Commit

Permalink
Merge branch '2.8' into 2.9
Browse files Browse the repository at this point in the history
  • Loading branch information
cowtowncoder committed Sep 12, 2019
2 parents a498dd8 + 73c1c2c commit e239b0d
Show file tree
Hide file tree
Showing 3 changed files with 11 additions and 3 deletions.
4 changes: 4 additions & 0 deletions release-notes/CREDITS-2.x
Expand Up @@ -661,6 +661,10 @@ svarzee@github
* Reported #2109, suggested fix: Canonical string for reference type is built incorrectly
(2.8.11.3 / 2.9.7)

Kaki King (kingkk9279@g)
* Reported #2449: Block one more gadget type (cve CVE-2019-14540)
(2.9.10)

Connor Kuhn (ckuhn@github)
* Contributed #1341: FAIL_ON_MISSING_EXTERNAL_TYPE_ID_PROPERTY
(2.9.0)
Expand Down
8 changes: 5 additions & 3 deletions release-notes/VERSION-2.x
Expand Up @@ -13,13 +13,15 @@ Project: jackson-databind
#2387: Block yet another deserialization gadget (CVE-2019-14379)
#2389: Block yet another deserialization gadget (CVE-2019-14439)
(reported by xiexq)
#2404: FAIL_ON_MISSING_EXTERNAL_TYPE_ID_PROPERTY setting ignored when
creator properties are buffered
(contributed by Joe B)
#2410: Block one more gadget type (CVE-2019-14540)
(reported by iSafeBlue@github / blue@ixsec.org)
#2420: Block one more gadget type (no CVE allocated yet)
(reported by crazylirui@gmail.com)
#2404: FAIL_ON_MISSING_EXTERNAL_TYPE_ID_PROPERTY setting ignored when
creator properties are buffered
(contributed by Joe B)
#2449: Block one more gadget type (no CVE allocated yet)
(reported by Kaki K)

2.9.9 (16-May-2019)

Expand Down
Expand Up @@ -98,6 +98,8 @@ public class SubTypeValidator

// [databind#2410]: HikariCP/metricRegistry config
s.add("com.zaxxer.hikari.HikariConfig");
// [databind#2449]: and sub-class thereof
s.add("com.zaxxer.hikari.HikariDataSource");

// [databind#2420]: CXF/JAX-RS provider/XSLT
s.add("org.apache.cxf.jaxrs.provider.XSLTJaxbProvider");
Expand Down

0 comments on commit e239b0d

Please sign in to comment.