{"id":"GHSA-qq48-m4jx-xqh8","summary":"\"Deserialization errors in MyBatis\"","details":"MyBatis before 3.5.6 mishandles deserialization of object streams leading to potential cache poisoning.","aliases":["CVE-2020-26945"],"modified":"2023-11-08T04:03:20.769862Z","published":"2021-04-22T16:14:38Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-04-21T19:54:50Z","nvd_published_at":"2020-10-10T20:15:00Z","cwe_ids":["CWE-502"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26945"},{"type":"WEB","url":"https://github.com/mybatis/mybatis-3/pull/2079"},{"type":"WEB","url":"https://github.com/mybatis/mybatis-3/releases/tag/mybatis-3.5.6"}],"affected":[{"package":{"name":"org.mybatis:mybatis","ecosystem":"Maven","purl":"pkg:maven/org.mybatis/mybatis"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.5.6"}]}],"versions":["2.3.5","3.0.1","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.1.0","3.1.1","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.3.0","3.3.1","3.4.0","3.4.1","3.4.2","3.4.3","3.4.4","3.4.5","3.4.6","3.5.0","3.5.1","3.5.2","3.5.3","3.5.4","3.5.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-qq48-m4jx-xqh8/GHSA-qq48-m4jx-xqh8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}