SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2, 2.8.11.4, and 2.7.9.6 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.
{ "nvd_published_at": "2019-07-29T12:15:00Z", "cwe_ids": [ "CWE-1321", "CWE-915" ], "severity": "CRITICAL", "github_reviewed": true, "github_reviewed_at": "2019-08-01T15:38:02Z" }