diff --git a/release-notes/VERSION b/release-notes/VERSION index 8c6835c53..253d056cc 100644 --- a/release-notes/VERSION +++ b/release-notes/VERSION @@ -67,6 +67,7 @@ One more patch release for 1.9. * [databind#2462]: Block two more gadget types (commons-configuration/-2, CVE-2019-14892) * [databind#2469]: Block one more gadget type (xalan2, might be related to CVE-2019-14893) * [databind#2704]: Block one more gadget type (xalan2, CVE-2020-14062) +* [databind#2765]: Block one more gadget type (org.jsecurity, 2020-14195) 1.9.13 (14-Jul-2013) diff --git a/src/mapper/java/org/codehaus/jackson/map/jsontype/impl/SubTypeValidator.java b/src/mapper/java/org/codehaus/jackson/map/jsontype/impl/SubTypeValidator.java index 535bb100f..0449fd656 100644 --- a/src/mapper/java/org/codehaus/jackson/map/jsontype/impl/SubTypeValidator.java +++ b/src/mapper/java/org/codehaus/jackson/map/jsontype/impl/SubTypeValidator.java @@ -184,6 +184,9 @@ public class SubTypeValidator s.add("oracle.jms.AQjmsXAQueueConnectionFactory"); s.add("oracle.jms.AQjmsXAConnectionFactory"); + // [databind#2764]: org.jsecurity: + s.add("org.jsecurity.realm.jndi.JndiRealmFactory"); + DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s); }