Is the dependent jars can be upgraded

Hi team,

We are using the elastic search 7.2.0 which depends on snakeyaml version 1.17.
Snakeyaml 1.17 has security vulnerabilities and we plan to upgrade it to the latest version 1.28.

Is upgrading the dependant snakeyaml jars alone, recommended?
Will elastic search works with snakeyaml 1.28 or do we have to stick with snakeyaml 1.17?

Thanks,
Mohammed

Welcome!

The recommendation is to upgrade Elasticsearch to 7.12.0 which is the latest.

2 Likes

And, to be clear, that is the only supported upgrade path to resolve issues like this.
If you start upgrading individual JARs, you are running risks that we cannot help fix if things go wrong.

2 Likes

Thanks, @dadoonet, and @warkolm for the quick reply