Description
MyBatis before 3.5.6 mishandles deserialization of object streams.
Remediation
References
https://github.com/mybatis/mybatis-3/compare/mybatis-3.5.5...mybatis-3.5.6
https://github.com/mybatis/mybatis-3/pull/2079
Related Vulnerabilities
CVE-2017-1000355 Vulnerability in maven package org.jenkins-ci.main:jenkins-core
CVE-2023-45648 Vulnerability in maven package org.apache.tomcat:tomcat
CVE-2018-14042 Vulnerability in maven package org.webjars.npm:bootstrap-sass
CVE-2020-26939 Vulnerability in maven package org.bouncycastle:bcprov-jdk14