Skip to content

Commit bf261d4

Browse files
committed
Merge branch '2.8' into 2.9
2 parents 822d3cb + 7487cf7 commit bf261d4

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

src/main/java/com/fasterxml/jackson/databind/jsontype/impl/SubTypeValidator.java

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -61,6 +61,12 @@ public class SubTypeValidator
6161
// [databind#2032]: more 3rd party; data exfiltration via xml parsed ext entities
6262
s.add("org.apache.ibatis.parsing.XPathParser");
6363

64+
// [databind#2052]: ldap approaches; in all cases LDAP connection String is passed
65+
// and access attempt is made:
66+
s.add("oracle.jdbc.connector.OracleManagedConnectionFactory");
67+
s.add("jodd.db.connection.DataSourceConnectionProvider");
68+
s.add("oracle.jdbc.rowset.OracleJDBCRowSet");
69+
6470
DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s);
6571
}
6672

0 commit comments

Comments
 (0)