Vendor
mchange-commons-java versions prior to 0.6.0 are susceptible to JNDI injection and deserialization gadget attacks due to insecure ObjectFactory implementations and the ReferenceIndirector mechanism.