On 4 Jul 2019, at 2:42, Tatu Saloranta wrote:
As per title, `2.9.9.1` of `jackson-databind` was released (ahead of
full `2.9.10` that will take longer), and contains fixes to 2 CVEs (of
polymorphic deser variety, see
Tatu,
I don't see an announcement of 2.9.9.2 of jackson-databind in the forum, but I noticed when I resolved against it, I found an issue relating to the jdk8 module.
I've pushed a test project to https://github.com/talios/broken-jackson-databind
When I drop the jackson databank down to 2.9.9.1 - both tests pass. With 2.9.9.2 only the test not using the Jdk8 module works.
Hopefully this is a simple issue and a 2.9.9.3 can be rolled before 2.9.10?
Cheers
Mark
"The ease with which a change can be implemented has no relevance at all to whether it is the right change for the (Java) Platform for all time." — Mark Reinhold.
Mark Derricutt
http://www.theoryinpractice.net
http://www.chaliceofblood.net
http://plus.google.com/+MarkDerricutt
http://twitter.com/talios
http://facebook.com/mderricutt