Description
MyBatis before 3.5.6 mishandles deserialization of object streams.
Remediation
References
https://github.com/mybatis/mybatis-3/compare/mybatis-3.5.5...mybatis-3.5.6
https://github.com/mybatis/mybatis-3/pull/2079
Related Vulnerabilities
CVE-2022-4111 Vulnerability in npm package tooljet
CVE-2022-37616 Vulnerability in maven package org.webjars.npm:xmldom
CVE-2020-2300 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2023-41592 Vulnerability in npm package froala-editor
CVE-2020-14967 Vulnerability in maven package org.webjars.bowergithub.kjur:jsrsasign