Vulnerability in MyBatis before 3.5.6 

Issue date: 08-12-2020
Affects versions: 14.3, 13.4, 12.6

Security Issue ID

SECURITY-192

 

Affected Product Version(s)

13.4.6, 12.6.13, 14.3.3 (and previous patch releases)


Severity 

medium


Description

MyBatis before 3.5.6 mishandles deserialization of object streams. brXM has been updated to the latest 3.5.6 version.

See CVE-2020-26945.

Instructions

Customers are recommended to upgrade to the latest maintenance or minor releases as indicated above. This can be done by simply incrementing the version number of the parent POM for the implementation project.