Can we just replace the snakeyaml-1.33.jar to snakeyaml-2.0.jar in opa-libs in apache-skywalking-apm-bin( version 9.3.0) #12129
Unanswered
DeBruyne2020
asked this question in
Q&A
Replies: 2 comments 2 replies
-
This is hard to tell. 2.0 compatibility is unknown. |
Beta Was this translation helpful? Give feedback.
1 reply
-
No. It requires code changes so you can’t simply replace the lib in the distribution tar |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We dont want to upgrade our jdk verision,(which the jdk we use is jdk 8) so the highest version of skywalking-oap we can use is version 9.3.0.
We need to solve the CVE-2022-1471 about snakeyaml.To solve the CVE-2022-1471 about snakeyaml we need to upgrade the snakeyaml version to 2.0.
My question is can we just replace the snakeyaml-1.33.jar to snakeyaml-2.0.jar in opa-libs in apache-skywalking-apm-bin( version 9.3.0) ?
Can skywalking work normal by this operation?
🙏
Beta Was this translation helpful? Give feedback.
All reactions