Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).
Remediation
References
Related Vulnerabilities
WordPress Plugin Product Catalog PHP Object Injection (4.2.25)
Ampache Improper Authentication Vulnerability (CVE-2007-4438)
Atlassian Jira Incorrect Authorization Vulnerability (CVE-2020-36238)
WordPress 2.2.1 Multiple Vulnerabilities (2.2.1)
WordPress Plugin EZ Google Analytics Cross-Site Scripting (4.1.06)