CVE advisoryCRITICAL
CVE-2018-11307
Jackson Databind Default Typing Vulnerability Allows Data Exfiltration.
Halo Surface Signal: 3 out of 5 — possibly public-facing.
A vulnerability in a JSON processing library allows unauthorized content exfiltration when default typing is enabled and specific gadget classes are present. This could expose sensitive information from systems handling JSON data, requiring careful review of library usage and default typing configurations.