diff --git a/release-notes/VERSION b/release-notes/VERSION index 66ce44341c..eaf12f3f5b 100644 --- a/release-notes/VERSION +++ b/release-notes/VERSION @@ -10,6 +10,7 @@ Project: jackson-databind (reported by vboulaye@github) #1628: Don't print to error stream about failure to load JDK 7 types (reported by Villane@github) +#1680: Blacklist couple more types for deserialization 2.7.9.1 (18-Apr-2017) diff --git a/src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializerFactory.java b/src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializerFactory.java index 586513ddd4..f2244e0c3d 100644 --- a/src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializerFactory.java +++ b/src/main/java/com/fasterxml/jackson/databind/deser/BeanDeserializerFactory.java @@ -58,6 +58,8 @@ public class BeanDeserializerFactory s.add("org.springframework.beans.factory.ObjectFactory"); s.add("com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl"); s.add("org.apache.xalan.xsltc.trax.TemplatesImpl"); + // [databind#1680]: may or may not be problem, take no chance + s.add("com.sun.rowset.JdbcRowSetImpl"); DEFAULT_NO_DESER_CLASS_NAMES = Collections.unmodifiableSet(s); }