Description
MyBatis before 3.5.6 mishandles deserialization of object streams.
Remediation
References
https://github.com/mybatis/mybatis-3/compare/mybatis-3.5.5...mybatis-3.5.6
https://github.com/mybatis/mybatis-3/pull/2079
Related Vulnerabilities
CVE-2022-45392 Vulnerability in maven package io.jenkins.plugins:cavisson-ns-nd-integration
CVE-2020-2117 Vulnerability in maven package org.jenkins-ci.plugins:pipeline-githubnotify-step
CVE-2023-36106 Vulnerability in maven package tech.powerjob:powerjob