# Fixing snakeyaml vulnerability (CVE-2022-1471) on older ES versions

**URL:** <https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571>\
**Category:** Elasticsearch\
**Tags:** docker\
**Created:** [March 13, 2023, 2:41pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571 "2023-03-13T14:41:27Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![Aviv\_Nevo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviv_nevo/32/118014_2.png) [@Aviv\_Nevo](https://discuss.elastic.co/u/Aviv_Nevo)\
**Post date:** [March 16, 2023, 1:24pm UTC](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571/5 "2023-03-16T13:24:40Z")

</div>

Thanks @frens !  
So it seems like this CVE still exists in latest ES version ☹

I've posted a [new topic](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854) on that - mainly to understand the plan to fix it, and how I can change this package version manually.

---

_[View the full topic](https://discuss.elastic.co/t/fixing-snakeyaml-vulnerability-cve-2022-1471-on-older-es-versions/327571)._
