Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
Remediation
References
Related Vulnerabilities
WordPress Plugin Database Backup for WordPress Cross-Site Scripting (2.3.3)
WordPress Plugin Smash Balloon Social Post Feed Security Bypass (4.0)
OpenSSL Out-of-bounds Read Vulnerability (CVE-2017-3731)
WordPress Plugin Download from files Arbitrary File Upload (1.48)
WordPress Plugin MasterStudy LMS-for Online Courses and Education SQL Injection (3.2.5)