I have a question :
the elasticsearch that I use now( version 7.11.2) has CVE-2022-1471 (about snakeyaml), which version of elasticsearch solve this problem ? (As I know, snakeyaml need bump to 2.0 version which solve the CVE-2022-1471 ) ,
Welcome! I suggest looking at the security announcement here for the details. It states that in general, Elasticsearch does not use Snakeyaml to parse YAML, but does note that it was removed as a direct dependency in v8.3.0 and the transitive dependency was upgraded to snakeyaml 2.0 in v8.8.0:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.