(cherry picked from commit 70c26703f462e97361924eaf6cbf80be1fce309f)
@@ -32,6 +32,9 @@ Release 2.6.3 - UNRELEASED
HADOOP-12526. there are duplicate dependency definitions in pom's (sjlee)
+ HADOOP-12577. Bumped up commons-collections version to 3.2.2 to address a
+ security flaw. (Wei-Chiu Chuang via vinodkv)
+
Release 2.6.2 - 2015-10-28
INCOMPATIBLE CHANGES
@@ -659,7 +659,7 @@
<dependency>
<groupId>commons-collections</groupId>
<artifactId>commons-collections</artifactId>
- <version>3.2.1</version>
+ <version>3.2.2</version>
</dependency>
<groupId>commons-configuration</groupId>