CVE-2018-14719
FasterXML Jackson-databind Polymorphic Deserialization Code Execution Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical vulnerability in the FasterXML jackson-databind library may permit remote attackers to execute arbitrary code by exploiting how certain classes are handled during data deserialization. This flaw, which can be reached via the network, allows for code execution on affected systems and potential compromise. Con