We are using the elastic search 7.2.0 which depends on snakeyaml version 1.17.
Snakeyaml 1.17 has security vulnerabilities and we plan to upgrade it to the latest version 1.28.
Is upgrading the dependant snakeyaml jars alone, recommended?
Will elastic search works with snakeyaml 1.28 or do we have to stick with snakeyaml 1.17?
And, to be clear, that is the only supported upgrade path to resolve issues like this.
If you start upgrading individual JARs, you are running risks that we cannot help fix if things go wrong.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.