Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
Remediation
References
Related Vulnerabilities
WordPress Plugin Slider by 10Web-Responsive Image Slider Unspecified Vulnerability (1.1.9)
MySQL Use After Free Vulnerability (CVE-2019-7317)
Magento Improper Access Control Vulnerability (CVE-2021-36036)
Atlassian Jira CVE-2021-26076 Vulnerability (CVE-2021-26076)
Squid Improper Input Validation Vulnerability (CVE-2016-2572)