[VOTE][CANCELLED] staging-1071 - tomee-1.7.3

2015-12-02 Thread Andy Gumbrecht
In order to provide users with the Apache Commons Collections 3.2.2 critical security fix this vote is cancelled. The issue remains a general problem in usages of ObjectInputStream, which should still filter at least known vulnerable classes. Andy. -- Andy Gumbrecht

Re: [VOTE][CANCELLED] staging-1071 - tomee-1.7.3

2015-12-02 Thread Romain Manni-Bucau
we dont need to cancel this one, we can do a 1.7.4 tomorrow if needed. There are still a very big part which is usable without the need of this fix. Romain Manni-Bucau @rmannibucau | Blog | Github