CVE advisoryCRITICAL
CVE-2019-14379
Jackson Databind Default Typing Remote Code Execution via Ehcache
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in FasterXML jackson-databind, when using ehcache, can allow remote code execution. This occurs due to improper handling of default typing, enabling an attacker to run arbitrary code over the network without authentication. This could affect system integrity and data confidentiality.