# Snakeyaml vulnerability (CVE-2022-1471) on latest ES version

**URL:** <https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [March 16, 2023, 1:13pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854 "2023-03-16T13:13:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aviv\_Nevo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aviv_nevo/32/118014_2.png) [@Aviv\_Nevo](https://discuss.elastic.co/u/Aviv_Nevo)\
**Post date:** [March 16, 2023, 1:13pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854/1 "2023-03-16T13:13:30Z")

</div>

Hi

Need help regarding CVE-2022-1471 (snakeyaml):

1. Is there any fix for that in any ES version?  
AFAIK, in the latest version, this package hasn't been updated.
2. Is there any plan to update the damaged package of snakeyaml?
3. Can I manually change the snakeyaml version? and how? (elasticsearch.yml maybe?)

The main reason this change is required is that we can't upload new images to GCP marketplace due to this vulnerability that is caused by ES.

---

<div class="post-metadata">

**Author:** ![DavidTurner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidturner/32/22453_2.png) [@DavidTurner](https://discuss.elastic.co/u/DavidTurner)\
**Post date:** [March 16, 2023, 3:02pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854/2 "2023-03-16T15:02:50Z")

</div>

We would rather not discuss potential security issues here. Please see this page for more information on the proper process to raise such issues:

> **[Security issues](https://www.elastic.co/community/security)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2023, 3:02pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-cve-2022-1471-on-latest-es-version/327854/3 "2023-04-13T15:02:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
