You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note: there is some suspicion that class blocked might not, in fact, be exploitable, by attackers.
But block is added in abundance of caution as there does not seem to be any chance type would have legit uses.
In general, however, we try to limit to real threats and not include speculative blocks.
Another gadget type reported regarding a class of
shiro-core
package.See https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062 for description of the general problem.
Reporter: (not public)
Fix will be included in:
jackson-bom
version2.8.11.20200310
)The text was updated successfully, but these errors were encountered: