Hello,
We are writing to inform you of a security vulnerability for GoCD. There is a patch available, and it is recommended to apply it as soon as possible. Please see this blog post (http://www.go.cd/2015/11/09/deserialization-vulnerability-commons-collections.html) for more information. Any updates regarding this vulnerability will be available on that post.
Regards,