# SnakeYAML vulnerability with latest Logstash version

**URL:** <https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332>\
**Category:** Logstash\
**Created:** [May 12, 2023, 5:08pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332 "2023-05-12T17:08:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nikhil\_Khurana](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nikhil_khurana/32/119984_2.png) [@Nikhil\_Khurana](https://discuss.elastic.co/u/Nikhil_Khurana)\
**Post date:** [May 12, 2023, 5:08pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332/1 "2023-05-12T17:08:13Z")

</div>

Hi,  
In the latest version of Logstash, SnakeYAML dependency was bumped to 1.33 but it seems that is vulnerable as well. The vulnerability [CVE-2022-1471](https://nvd.nist.gov/vuln/detail/CVE-2022-1471) is a critical one with score of 9.8.  
Are there plans to bump it to 2.0 in next release?  
Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 14, 2023, 11:29pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332/2 "2023-05-14T23:29:26Z")

</div>

Please see [Security issues | Elastic](https://www.elastic.co/community/security);

> Users and customers may report any other potential security issues to [security@elastic.co](mailto:security@elastic.co). This address can be used for product security related inquiries or requests about other security topics that are not explicitly mentioned here. We can accept only security issues at this address. Bug reports should be directed to the bug database of the project you're reporting it on or raised to Elastic Support.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 11, 2023, 11:30pm UTC](https://discuss.elastic.co/t/snakeyaml-vulnerability-with-latest-logstash-version/333332/3 "2023-06-11T23:30:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
