# Elasticsearch 7.17 and logstash7.17 have security issues with snakeyaml low versions and need to be upgraded to 2.0 or higher

**URL:** <https://discuss.elastic.co/t/elasticsearch-7-17-and-logstash7-17-have-security-issues-with-snakeyaml-low-versions-and-need-to-be-upgraded-to-2-0-or-higher/369855>\
**Category:** Elasticsearch\
**Created:** [October 31, 2024, 1:26am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-and-logstash7-17-have-security-issues-with-snakeyaml-low-versions-and-need-to-be-upgraded-to-2-0-or-higher/369855 "2024-10-31T01:26:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![wb\_he](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wb_he/32/138842_2.png) [@wb\_he](https://discuss.elastic.co/u/wb_he)\
**Post date:** [October 31, 2024, 1:26am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-and-logstash7-17-have-security-issues-with-snakeyaml-low-versions-and-need-to-be-upgraded-to-2-0-or-higher/369855/1 "2024-10-31T01:26:32Z")

</div>

I am currently using Elasticsearch 7.17.14 and Logstash7.17.14. Scanning shows that both of these applications are using the snakeyaml 1.0 version jar package, and there are security issues with snakeyaml versions smaller than 2.0. I hope to upgrade snakeyaml to version 2.0 or above through a minor version in version 7.17. thank you!

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [October 31, 2024, 3:22am UTC](https://discuss.elastic.co/t/elasticsearch-7-17-and-logstash7-17-have-security-issues-with-snakeyaml-low-versions-and-need-to-be-upgraded-to-2-0-or-higher/369855/2 "2024-10-31T03:22:21Z")

</div>

Per the instructions here:

- [Security issues | Elastic](https://www.elastic.co/community/security)

Reports of potential security issues, including CVEs in dependencies should be reported to our security team. We do not discuss them here.
