Description
FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
Remediation
References
Related Vulnerabilities
Python Files or Directories Accessible to External Parties Vulnerability (CVE-2019-13404)
WordPress 4.2.x Prototype Pollution (4.2 - 4.2.31)
WordPress Plugin HTML5 Video Player-Best WordPress Video Player and Block SQL Injection (2.5.26)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2021-37147)