Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
Remediation
References
Related Vulnerabilities
WordPress Plugin BePro Listings Arbitrary File Upload (2.2.0020)
WordPress Plugin WP-Filebase Download Manager 'base' Parameter SQL Injection (0.2.9)
Perl Improper Certificate Validation Vulnerability (CVE-2023-31486)
WordPress Plugin Conditional Marketing Mailer for WooCommerce Unspecified Vulnerability (1.6)