Description
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Remediation
References
Related Vulnerabilities
Perl Out-of-bounds Write Vulnerability (CVE-2022-48522)
MySQL CVE-2022-21637 Vulnerability (CVE-2022-21637)
MySQL CVE-2022-21600 Vulnerability (CVE-2022-21600)
WordPress Plugin ThemeHigh WooCommerce Wishlist and Comparison Cross-Site Request Forgery (1.0.4)
Moodle Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2020-14322)