Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Cross-Site Scripting (3.0.0 - 3.9.15)
phpMyFAQ Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2017-15730)
Ruby CVE-2018-16396 Vulnerability (CVE-2018-16396)
OpenSSL Out-of-bounds Write Vulnerability (CVE-2016-6303)
WeBid Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-7117)