Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).
Remediation
References
Related Vulnerabilities
Roundcube Cross-site Scripting (XSS) Vulnerability (CVE-2016-4068)
WordPress Plugin WP Smiley Multiple Vulnerabilities (1.4.1)
WordPress Plugin Powerplay Gallery Multiple Vulnerabilities (3.3)
Squid Improper Input Validation Vulnerability (CVE-2014-7142)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3810)