Description
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Remediation
References
Related Vulnerabilities
WordPress Plugin YAS Slideshow Arbitrary File Upload (3.4)
Coppermine Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-1614)
WordPress Other Vulnerability (CVE-2005-2109)
PHP Other Vulnerability (CVE-2007-1710)
WordPress Plugin TablePress XML External Entity Injection (1.8)