jackson-databind can deserialize untrusted data. The vulnerability is due to an incomplete fix for the CVE-2017-7525.
access.redhat.com/errata/RHBA-2019:0959
access.redhat.com/errata/RHSA-2019:0782
access.redhat.com/errata/RHSA-2019:1106
access.redhat.com/errata/RHSA-2019:1107
access.redhat.com/errata/RHSA-2019:1108
access.redhat.com/errata/RHSA-2019:1140
access.redhat.com/errata/RHSA-2019:1822
access.redhat.com/errata/RHSA-2019:1823
access.redhat.com/errata/RHSA-2019:2858
github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44
github.com/FasterXML/jackson-databind/issues/2097
github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7
lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E
lists.debian.org/debian-lts-announce/2019/03/msg00005.html
seclists.org/bugtraq/2019/May/68
security.netapp.com/advisory/ntap-20190530-0003/
www.debian.org/security/2019/dsa-4452
www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html