Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig (aka ibatis-sqlmap).
Remediation
References
Related Vulnerabilities
Dolibarr Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2021-25957)
WordPress Plugin WP Table Builder-WordPress Table Cross-Site Scripting (1.4.6)
WordPress Plugin NextScripts:Social Networks Auto-Poster Cross-Site Scripting (4.2.7)