Hi Moritz,
Am Freitag, den 22.01.2021, 21:03 +0100 schrieb Moritz Muehlenhoff:
I believe starting with 2.10 this is no longer security relevant because
developers are required "to specify validator of type PolymorphicTypeValidator
that will determine if deserialization of given class name is (or is not)
allowed." (quote from the second link, the official announcement by upstream)
That means a developer of a dependency of jackson-databind is still allowed to
shoot oneself in the foot but you can't blame jackson-databind for it anymore.
So beginning with 2.10 I would simply ignore similar issues in the security
tracker.
Regards,
Markus