Description
MyBatis before 3.5.6 mishandles deserialization of object streams.
Remediation
References
https://github.com/mybatis/mybatis-3/compare/mybatis-3.5.5...mybatis-3.5.6
https://github.com/mybatis/mybatis-3/pull/2079
Related Vulnerabilities
CVE-2022-29577 Vulnerability in maven package org.owasp:antisamy
CVE-2021-22112 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2020-2271 Vulnerability in maven package org.jenkins-ci.plugins:locked-files-report
CVE-2016-10573 Vulnerability in npm package baryton-saxophone