Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Remediation
References
Related Vulnerabilities
WordPress Plugin Googmonify Multiple Vulnerabilities (0.5.1)
WordPress Plugin Contact Form 'wpcf_easyform_formid' Parameter SQL Injection (2.7.5)
WordPress Plugin WP Open Graph Cross-Site Request Forgery (1.6.1)
WordPress Plugin LearnPress-WordPress LMS Security Bypass (4.1.4.1)
WordPress Plugin ApplyOnline-Application Form Builder and Manager Cross-Site Scripting (1.9.94)