Package
elasticsearch-7
Component
snakeyaml
Latest update
8.3
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
Elasticsearch is not affected by the issue described in CVE-2022-1471 as, in general, it does not use Snakeyaml to parse YAML. For more details, see https://discuss.elastic.co/t/elasticsearch-security-statement-regarding-cve-2022-1471/343006
Status