Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Directory Traversal (3.2.0 - 3.4.5)
WordPress Plugin Browser Screenshots Cross-Site Scripting (1.7.5)
MyBB Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-9410)
WordPress Plugin WP Support Plus Responsive Ticket System Privilege Escalation (7.1.4)