|
Author: jleroux
Revision: 1856405
Modified property: svn:log
Modified: svn:log at Fri Sep 13 07:29:16 2019
------------------------------------------------------------------------------
--- svn:log (original)
+++ svn:log Fri Sep 13 07:29:16 2019
@@ -1,6 +1,8 @@
Improved: Improve ObjectInputStream class
(OFBIZ-10837)
+Fixes CVE-2019-0189
+
The white list was still not complete as reported by Wolfgang Rauchholz on user
ML
This adds java.math.BigDecimal and "[B" (ie [B == byte[] and I don't understand
|