From 260944ec36d41076365d5ebf8f54cba2189a480f Mon Sep 17 00:00:00 2001 From: Mikolaj Izdebski Date: Tue, 2 Apr 2019 13:58:09 +0200 Subject: [PATCH 08/14] CVE-2018-14718 --- .../jackson/databind/jsontype/impl/SubTypeValidator.java | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java index 3a480272e..ba6d48cd3 100644 --- a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java +++ b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java @@ -57,6 +57,8 @@ public class SubTypeValidator // CVE-2018-12023 s.add("oracle.jdbc.connector.OracleManagedConnectionFactory"); s.add("oracle.jdbc.rowset.OracleJDBCRowSet"); + // CVE-2018-14718 + s.add("org.slf4j.ext.EventData"); DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s); } -- 2.20.1