Description
MyBatis before 3.5.6 mishandles deserialization of object streams.
Remediation
References
https://github.com/mybatis/mybatis-3/compare/mybatis-3.5.5...mybatis-3.5.6
https://github.com/mybatis/mybatis-3/pull/2079
Related Vulnerabilities
CVE-2017-11556 Vulnerability in npm package node-sass
CVE-2021-21306 Vulnerability in maven package org.webjars.npm:marked
CVE-2016-8750 Vulnerability in maven package org.apache.karaf.jaas:org.apache.karaf.jaas.modules
CVE-2014-7810 Vulnerability in maven package org.mortbay.jasper:apache-el
CVE-2023-37963 Vulnerability in maven package io.jenkins.plugins:benchmark-evaluator