CVE advisoryCRITICAL
CVE-2019-16943
FasterXML Jackson Polymorphic Typing Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A vulnerability in FasterXML jackson-databind, when Default Typing is enabled for an externally exposed JSON endpoint and the p6spy jar is present, could allow an attacker to execute malicious code by targeting an RMI service. This impacts services processing untrusted JSON input with specific dependencies.