Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Remediation
References
Related Vulnerabilities
WordPress Plugin WooCommerce Upload My File Cross-Site Request Forgery (0.3.9)
WordPress Plugin Divi Builder Cross-Site Scripting (2.17.2)
Joomla! Core Multiple SQL Injection Vulnerabilities (2.5.0 - 3.9.13)
PHP Data Processing Errors Vulnerability (CVE-2015-4147)
WordPress Plugin Browser Rejector Remote File Inclusion (2.10)