Replies: 1 comment
|
@arungitan Code paths are quite different, as This means CVE as-is does NOT relate to |
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
@cowtowncoder @pjfanning I know the verbiage of CVE-2026-54515 (fixed by #5962) explicitly mentions only
@JsonIgnorePropertiesbut it also specifically says "per-property usage".The confusion: My understanding is the "per-property use of
@JsonIgnorePropertieswould have the same functional behavior as using@JsonIgnoreon that property. Hence wanted to clarify/confirm whether the internal handling of@JsonIgnoreis a different codepath and is therefore completely unaffected by this CVE or whether we should consider usage of@JsonIgnoreas well when assessing our code?All reactions