Description
MyBatis before 3.5.6 mishandles deserialization of object streams.
Remediation
References
https://github.com/mybatis/mybatis-3/compare/mybatis-3.5.5...mybatis-3.5.6
https://github.com/mybatis/mybatis-3/pull/2079
Related Vulnerabilities
CVE-2021-23566 Vulnerability in npm package nanoid
CVE-2020-2198 Vulnerability in maven package hudson.plugins:project-inheritance
CVE-2022-28158 Vulnerability in maven package com.surenpi.jenkins:phoenix-autotest
CVE-2022-39299 Vulnerability in npm package passport-saml
CVE-2018-16472 Vulnerability in maven package org.webjars.npm:cached-path-relative