logo

Vulnerability details for CVE-2020-26945 

MyBatis before 3.5.6 mishandles deserialization of object streams.

CVSS Score (Vector) 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P)
ThreatWorx Rating 3 - Severe
Weakness Types Deserialization of Untrusted Data, Code Execution
Reported By Open Source, Red Hat, GitHub
First Reported Oct 10, 2020 by Open Source
Last Updated Aug 11, 2021 by Red Hat
NVD Status Published CVE-2020-26945
Affected Products 5 affected product(s) reported by NVD, Open Source, Red Hat, GitHub
Patches No known patches
Remediations 2 remediation(s) published by Open Source, GitHub
Latest Reference Red Hat