www-announce mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Thomas Neidhart ...@apache.org>
Subject [ANNOUNCEMENT] Apache Commons Collections 3.2.2 Released
Date Sun, 15 Nov 2015 22:24:26 GMT
The Apache Commons team is pleased to announce the release of Apache
Commons Collections 3.2.2. The release is available for download at


Apache Commons Collections is a project to develop and maintain
collection classes based on and inspired by the JDK collection framework.

This Collections 3.2.2 release is a security and bugfix release, fixing
several bugs present in the previous releases of the 3.2 branch.

Additionally, this release provides a mitigation for a known remote code
exploitation via the standard java object serialization mechanism. By
default, serialization support for unsafe classes in the functor package
is disabled and will result in an exception when either trying to
serialize or de-serialize an instance of these classes. For more
details, please refer to COLLECTIONS-580.

All users are strongly encouraged to updated to this release.

See the release-notes at


for a full list of changes.

Please verify signatures using the KEYS file available at the above
location when downloading the release.

For complete information on collections, including instructions on how
to submit bug reports, patches, or suggestions for improvement, see the
Apache Commons Collections website:


Thomas, on behalf of the Apache Commons team

View raw message