Description
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
Remediation
References
Related Vulnerabilities
WordPress Plugin Tune Library 'letter' Parameter SQL Injection (1.5.1)
MySQL CVE-2014-0386 Vulnerability (CVE-2014-0386)
WordPress Plugin WP Legal Pages Cross-Site Scripting (1.0.1)
Undertow Insertion of Sensitive Information into Log File Vulnerability (CVE-2019-10212)
XWiki Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-35151)