SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2, 2.8.11.4, and 2.7.9.6 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
{
"severity": "CRITICAL",
"nvd_published_at": "2019-07-29T12:15:00Z",
"github_reviewed_at": "2019-08-01T15:38:02Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-1321",
"CWE-915"
]
}