Description
FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.
Remediation
References
Related Vulnerabilities
ownCloud Improper Authentication Vulnerability (CVE-2016-9463)
WordPress Plugin Wordpress Countdown Widget Cross-Site Scripting (3.1.9.2)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4408)
Jboss EAP Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2018-10237)
WordPress Plugin Print Invoice & Delivery Notes for WooCommerce Cross-Site Scripting (4.7.1)