Skip to content

Commit

Permalink
Add ref from #2589 to CVE-2020-25649 in release notes for 2.11.0
Browse files Browse the repository at this point in the history
  • Loading branch information
cowtowncoder committed Oct 13, 2020
1 parent 8b75ed4 commit e588f0a
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion release-notes/VERSION-2.x
Original file line number Diff line number Diff line change
Expand Up @@ -96,7 +96,7 @@ Project: jackson-databind
#2587: Add `MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES` to allow blocking
use of unsafe base type for polymorphic deserialization
#2589: `DOMDeserializer`: setExpandEntityReferences(false) may not prevent
external entity expansion in all cases
external entity expansion in all cases [CVE-2020-25649]
(reported by Bartosz B)
#2592: `ObjectMapper.setSerializationInclusion()` is ignored for `JsonAnyGetter`
(reported by Oleksii K)
Expand Down

0 comments on commit e588f0a

Please sign in to comment.