当前使用版本(必填,否则不予处理)

mybatis-plus-boot-starter 3.5.3.1

该问题是如何引起的?(确定最新版也有问题再提!!!)

添加 com.baomidou mybatis-plus-boot-starter 3.5.3.1 到pom.xml

重现步骤(如果有就写完整)

添加 com.baomidou mybatis-plus-boot-starter 3.5.3.1 到pom.xml

报错信息

Provides transitive vulnerable dependency maven:org.yaml:snakeyaml:1.33 CVE-2022-41854 6.5 Out-of-bounds Write vulnerability with medium severity found CVE-2022-1471 9.8 Deserialization of Untrusted Data vulnerability with high severity found

Comment From: qmdx

https://github.com/baomidou/mybatis-plus/issues/4919