Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Gravity Forms Zoho CRM Add-on Cross-Site Scripting (1.1.5)
WordPress Plugin UpdraftPlus WordPress Backup Cross-Site Scripting (1.9.63)
WordPress Plugin Simple Contact Info Arbitrary File Deletion (1.1.9)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.13)
WordPress Plugin Image Gallery-Responsive Photo Gallery SQL Injection (1.0.6)