Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
Remediation
References
Related Vulnerabilities
WordPress Plugin ENL Newsletter SQL Injection (1.0.1)
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-7929)
MySQL CVE-2017-3309 Vulnerability (CVE-2017-3309)
WordPress Plugin Timeline Event History PHP Object Injection (3.1)
WordPress Plugin My WordPress Login Logo Multiple Unspecified Vulnerabilities (2.1)