Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
Remediation
References
Related Vulnerabilities
WordPress Plugin Advanced Custom Fields:reCAPTCHA Field Security Bypass (1.1.1)
WordPress Plugin Podlove Podcast Publisher Cross-Site Request Forgery (3.8.3)
Liferay DXP Improper Certificate Validation Vulnerability (CVE-2022-42131)
Joomla Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-10241)