CVE advisoryCRITICAL
CVE-2019-17531
Jackson Databind Polymorphic Typing Vulnerability
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical vulnerability in the FasterXML jackson-databind library allows for malicious payload execution when default typing is enabled for external JSON endpoints and the `apache-log4j-extra` library is present. Attackers can exploit this by providing a JNDI service, potentially leading to unauthorized code execution