Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Remediation
References
Related Vulnerabilities
WordPress Plugin Site Reviews Cross-Site Scripting (5.13.0)
WordPress Plugin WP-Contact Multiple Cross-Site Scripting Vulnerabilities (1.0)
OpenSSL Cryptographic Issues Vulnerability (CVE-2015-3197)
WordPress Plugin VO Store Locator-WP Store Locator Unspecified Vulnerability (3.2.14)
WordPress Plugin Xerte Online 'save.php' Arbitrary File Upload (0.32)