Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
Remediation
References
Related Vulnerabilities
EspoCRM Improper Neutralization of Formula Elements in a CSV File Vulnerability (CVE-2022-38845)
WordPress Plugin Trust Form Cross-Site Scripting (2.0)
WordPress Plugin Chameleoni Jobs Multiple Cross-Site Scripting Vulnerabilities (1.2.2)
Sqlite CVE-2021-36690 Vulnerability (CVE-2021-36690)
WordPress Plugin Password Protected Unspecified Vulnerability (2.0)