MyBatis before 3.5.6 mishandles deserialization of object streams.
References
Link | Resource |
---|---|
https://github.com/mybatis/mybatis-3/compare/mybatis-3.5.5...mybatis-3.5.6 | Third Party Advisory |
https://github.com/mybatis/mybatis-3/pull/2079 | Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2020-10-10T19:41:39
Updated: 2020-10-10T19:41:39
Reserved: 2020-10-10T00:00:00
Link: CVE-2020-26945
JSON object: View
NVD Information
Status : Analyzed
Published: 2020-10-10T20:15:11.900
Modified: 2020-10-26T15:17:03.967
Link: CVE-2020-26945
JSON object: View
Redhat Information
No data.
CWE