# Fixing snakeyaml vulnerability (CVE-2022-1471) on older ES versions

**URL:** <https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [March 13, 2023, 2:41pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571 "2023-03-13T14:41:27Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aviv\_Nevo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviv_nevo/32/118014_2.png) [@Aviv\_Nevo](https://discuss.elastic.co/u/Aviv_Nevo)\
**Post date:** [March 13, 2023, 2:41pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571/1 "2023-03-13T14:41:27Z")

</div>

I'm using ES version 5.6.X, and I would like to change snakeyaml package version to the one with the fix to CVE-2022-1471 - Meaning, I need to change the package version from 1.33 (I guess..) to 2.0 .

How can I do that?  
Should it be in my DockerFile? Or in elasticsearch.yml file?

---

<div class="post-metadata">

**Author:** ![TimV](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/timv/32/13162_2.png) [@TimV](https://discuss.elastic.co/u/TimV)\
**Post date:** [March 14, 2023, 5:03am UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571/2 "2023-03-14T05:03:15Z")

</div>

Elasticsearch 5 is very old and is no longer maintained.

We have never tested running Elasticsearch 5.6 with any version of SnakeYaml other than the one that it shipped with. It _might_ work, but there are no guarantees.

If you care about resolving vulnerabilities then you need to migrate to a maintained version of Elasticsearch. No one is patching vulnerabilities in Elasticsearch 5 (or 6) anymore.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2023, 5:03am UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571/3 "2023-03-14T05:03:15Z")

</div>

Elasticsearch 5.6 is [EOL](https://www.elastic.co/support/eol) and no longer supported. Please upgrade ASAP.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![frens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frens/32/114800_2.png) [@frens](https://discuss.elastic.co/u/frens)\
**Post date:** [March 14, 2023, 8:28pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571/4 "2023-03-14T20:28:17Z")

</div>

Note that this version of snakeyaml is also a dependency of `org.elasticsearch:elasticsearch-x-content:jar:7.17.9`.

See also the output of grype:

For 7.17.9:

```auto
# wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-7.17.9-linux-x86_64.tar.gz
...

# grype elasticsearch-7.17.9-linux-x86_64.tar.gz
 ✔ Vulnerability DB [no update available]
New version of grype is available: 0.59.1 (currently running: 0.57.1)
 ✔ Indexed /private/var/folders/yv/r54c6ptj6vz1s1937pc7v4mc0000gn/T/syft-archive-contents-4151449920
 ✔ Cataloged packages [286 packages]
 ✔ Scanned image [34 vulnerabilities]
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY

...
snakeyaml 1.33 2.0 java-archive GHSA-mjmj-j48q-9wg2 High
...

```

For 8.6.2:

```auto
# wget https://artifacts.elastic.co/downloads/elasticsearch/elasticsearch-8.6.2-linux-x86_64.tar.gz
...

# grype elasticsearch-8.6.2-linux-x86_64.tar.gz
 ✔ Vulnerability DB [no update available]
New version of grype is available: 0.59.1 (currently running: 0.57.1)
 ✔ Indexed /private/var/folders/yv/r54c6ptj6vz1s1937pc7v4mc0000gn/T/syft-archive-contents-86995759
 ✔ Cataloged packages [516 packages]
 ✔ Scanned image [71 vulnerabilities]
NAME INSTALLED FIXED-IN TYPE VULNERABILITY SEVERITY
...
snakeyaml 1.33 2.0 java-archive GHSA-mjmj-j48q-9wg2 High
...

```

[SnakeYaml Constructor Deserialization Remote Code Execution · CVE-2022-1471 · GitHub Advisory Database · GitHub](https://github.com/advisories/GHSA-mjmj-j48q-9wg2) listed by grype is about the mentioned CVE-2022-1471

---

<div class="post-metadata">

**Author:** ![Aviv\_Nevo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviv_nevo/32/118014_2.png) [@Aviv\_Nevo](https://discuss.elastic.co/u/Aviv_Nevo)\
**Post date:** [March 16, 2023, 1:24pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571/5 "2023-03-16T13:24:40Z")

</div>

Thanks @frens !  
So it seems like this CVE still exists in latest ES version ☹

I've posted a [new topic](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854) on that - mainly to understand the plan to fix it, and how I can change this package version manually.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [March 16, 2023, 3:02pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571/6 "2023-03-16T15:02:45Z")

</div>

We would rather not discuss potential security issues here. Please see this page for more information on the proper process to raise such issues:

> **[Security issues](https://www.elastic.co/community/security)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571/7 "2023-04-13T15:02:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
