Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2015-2595 Vulnerability (CVE-2015-2595)
Django Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2019-6975)
Envoy Proxy Improper Check for Unusual or Exceptional Conditions Vulnerability (CVE-2021-39162)
Django Other Vulnerability (CVE-2009-3695)
MediaWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2019-19709)