From e2ba12d5d60715d95105e3e790fc234cfb59893d Mon Sep 17 00:00:00 2001 From: Tatu Saloranta Date: Sat, 28 Mar 2020 12:52:17 -0700 Subject: [PATCH] Fix #2670 --- release-notes/VERSION-2.x | 2 ++ .../jackson/databind/jsontype/impl/SubTypeValidator.java | 3 ++- 2 files changed, 4 insertions(+), 1 deletion(-) diff --git a/release-notes/VERSION-2.x b/release-notes/VERSION-2.x index 1a27ccb870..3b2bcbec0c 100644 --- a/release-notes/VERSION-2.x +++ b/release-notes/VERSION-2.x @@ -26,6 +26,8 @@ Project: jackson-databind (reported by Srikanth Ramu) #2666: Block one more gadget type (apache/commons-proxy) (reported by Yiting Fan) +#2670: Block one more gadget type (openjpa) + (reported by XuYuanzhen) 2.9.10.3 (23-Feb-2020) diff --git a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java index bda0787525..e3962ca725 100644 --- a/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java +++ b/src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java @@ -74,10 +74,11 @@ public class SubTypeValidator s.add("com.sun.deploy.security.ruleset.DRSHelper"); s.add("org.apache.axis2.jaxws.spi.handler.HandlerResolverImpl"); - // [databind#2186]: yet more 3rd party gadgets + // [databind#2186], [databind#2670]: yet more 3rd party gadgets s.add("org.jboss.util.propertyeditor.DocumentEditor"); s.add("org.apache.openjpa.ee.RegistryManagedRuntime"); s.add("org.apache.openjpa.ee.JNDIManagedRuntime"); + s.add("org.apache.openjpa.ee.WASRegistryManagedRuntime"); // [#2670] addition s.add("org.apache.axis2.transport.jms.JMSOutTransportInfo"); // [databind#2326] (2.9.9)