Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).
Remediation
References
Related Vulnerabilities
Apache HTTP Server Resource Management Errors Vulnerability (CVE-2016-8740)
WordPress Plugin Crelly Slider Arbitrary File Upload (1.3.4)
WordPress Plugin Ivory Search-WordPress Search Multiple Cross-Site Scripting Vulnerabilities (5.4)
IBMHttpServer Observable Discrepancy Vulnerability (CVE-2023-32342)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-3835)