From 568e26502f2b20b5d60d832b6098c7efe6a37d50 Mon Sep 17 00:00:00 2001 From: Mikolaj Izdebski Date: Tue, 2 Apr 2019 13:59:58 +0200 Subject: [PATCH 13/14] CVE-2018-19361 --- .../jackson/databind/jsontype/impl/SubTypeValidator.java | 3 +++ 1 file changed, 3 insertions(+) diff --git a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java index 686ed1d42..8b3319b54 100644 --- a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java +++ b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java @@ -67,6 +67,9 @@ public class SubTypeValidator s.add("org.apache.axis2.jaxws.spi.handler.HandlerResolverImpl"); // CVE-2018-19360 s.add("org.apache.axis2.transport.jms.JMSOutTransportInfo"); + // CVE-2018-19361 + s.add("org.apache.openjpa.ee.RegistryManagedRuntime"); + s.add("org.apache.openjpa.ee.JNDIManagedRuntime"); DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s); } -- 2.20.1