Description
MyBatis before 3.5.6 mishandles deserialization of object streams.
Remediation
References
https://github.com/mybatis/mybatis-3/compare/mybatis-3.5.5...mybatis-3.5.6
https://github.com/mybatis/mybatis-3/pull/2079
Related Vulnerabilities
CVE-2022-25876 Vulnerability in npm package link-preview-js
CVE-2022-31051 Vulnerability in npm package semantic-release
CVE-2019-16761 Vulnerability in npm package slp-validate
CVE-2019-10158 Vulnerability in maven package org.infinispan:infinispan-spring5-embedded
CVE-2017-5636 Vulnerability in maven package org.apache.nifi:nifi-web-security