FasterXML jackson-databind 2.x before 2.6.7.5 and from 2.7.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.
{ "last_known_affected_version_range": "<= 2.6.7.4" }
{ "last_known_affected_version_range": "<= 2.9.10.5" }