// OSSeva Blog
MigrationCloudera CDH and HDP End of Life: Dates, the ZooKeeper Underneath, and Your Options
The short answer
Every release of Cloudera's Distribution including Apache Hadoop (CDH) and the Hortonworks Data Platform (HDP) is past end of support. The last dates were CDH 6.2 and 6.3 in March 2022 and HDP 3.1 in December 2021. Cloudera offered eligible customers a six-month Limited Support period after those dates, and it ended on 30 September 2022 for CDH and 30 June 2022 for HDP. Since then there have been no patches for either distribution.
The part that is easy to miss is underneath the Hadoop services. CDH 5 and CDH 6 bundle Apache ZooKeeper 3.4.5, and HDP bundles 3.4.6. The upstream ZooKeeper 3.4 line reached end of life on 1 June 2020, and CVE-2023-44981, a critical quorum authentication bypass, was published in October 2023 with no fix for 3.4. HDFS high availability, YARN ResourceManager failover, HBase and Hive all depend on that ensemble.
The options are the ones every CDH and HDP estate already knows: upgrade to Cloudera on premises (formerly CDP Private Cloud Base) 7.1.9 or 7.3.2, migrate to a cloud platform, or keep running with third-party patches for the coordination and data layers while the migration is planned.
CDH end-of-support dates
Cloudera's support lifecycle policy lists the end-of-support (EoS) month for each release and says the date can be taken as the last day of that month.
| CDH release | GA | End of support |
|---|---|---|
| CDH 6.3 | Jul 2019 | Mar 2022 |
| CDH 6.2 | Mar 2019 | Mar 2022 |
| CDH 6.1 | Dec 2018 | Dec 2021 |
| CDH 6.0 | Aug 2018 | Aug 2021 |
| CDH 5.14, 5.15, 5.16 | Dec 2020 | |
| CDH 5.13 | Oct 2020 | |
| CDH 5.12 | Jul 2020 | |
| CDH 5.11 | Apr 2020 | |
| CDH 5.10 | Jan 2020 | |
| CDH 5.9 | Oct 2019 | |
| CDH 5.8 and earlier | Aug 2019 |
Limited Support for eligible CDH 6.2 and 6.3 customers ran from 1 April 2022 to 30 September 2022.
HDP end-of-support dates
| HDP release | GA | End of support |
|---|---|---|
| HDP 3.1 | Dec 2018 | Dec 2021 |
| HDP 3.0 | Jul 2018 | Jul 2021 |
| HDP 2.6 | Apr 2017 | Dec 2020 |
| HDP 2.5 | Aug 2016 | Aug 2019 |
| HDP 2.4 | Mar 2016 | Mar 2019 |
| HDP 2.3 | Jul 2015 | Jul 2018 |
Limited Support for eligible HDP 3.1 customers ran from 1 January 2022 to 30 June 2022. HDP came to Cloudera through the merger with Hortonworks, completed on 3 January 2019, which is why both product families sit on one lifecycle page and why CDP was built to replace both of them.
Does a newer Cloudera Manager extend CDH support?
No. Cloudera's policy says so directly: using a newer Cloudera Manager version does not extend the lifetime of a CDH or Cloudera on premises version, and a cluster can reach end of support before the Cloudera Manager that manages it. Since Cloudera Manager 7.11.3, Cloudera Manager has its own dates, no longer tied to a runtime release.
| Cloudera Manager | GA | End of support |
|---|---|---|
| 7.13.2 | Mar 2026 | To be announced |
| 7.13.1 | Dec 2024 | Dec 2028 |
| 7.11.3 | Sep 2023 | Nov 2026 |
| 7.10.1 and below | Aug 2022 | Aug 2025 |
The Cloudera support lifecycle today
The supported on-premises product is what Cloudera now calls Cloudera on premises, formerly CDP Private Cloud Base, the on-premises form of Cloudera Data Platform. The 7.3.x releases are listed under the Cloudera platform, formerly CDP.
| Release | GA | End of support |
|---|---|---|
| 7.3.2 | Mar 2026 | Mar 2032 |
| 7.3.1 | Dec 2024 | Dec 2026 |
| 7.1.9 | Sep 2023 | Oct 2028 |
| 7.1.8 | Aug 2022 | Aug 2024 |
| 7.1.7 | Aug 2021 | Aug 2025 |
| 7.1.6 | Mar 2021 | Mar 2024 |
| 7.1 to 7.1.5 | May 2020 | May 2023 |
| 7.0 | Nov 2019 | Nov 2022 |
Two things stand out. The latest version of Cloudera on premises is 7.3.2, supported to March 2032. And 7.3.1 ends in December 2026, so a CDH migration that targets 7.3.1 today lands on a release with three months left. The policy page has a Long Term Support column, but which releases carry that designation is not something we could confirm from the published text, so check it with Cloudera for your target.
For context on the company: Cloudera was taken private by Clayton, Dubilier & Rice and KKR in a deal completed on 8 October 2021. The lifecycle policy, not the ownership, is what determines your support dates.
The hidden layer: ZooKeeper inside CDH, HDP and early CDP
Most CDH and HDP end-of-life planning looks at the big data services: HDFS, YARN, Hive, Impala, Apache Spark, HBase. The coordination service underneath them gets less attention, and it is the oldest code in the stack.
| Distribution | Bundled ZooKeeper | Upstream line status |
|---|---|---|
| CDH 5 (5.0 to 5.16) | 3.4.5, e.g. 3.4.5+cdh5.16.2+159 | 3.4 end of life 1 Jun 2020 |
| CDH 6 (6.0 and 6.3.x) | 3.4.5 | 3.4 end of life 1 Jun 2020 |
| HDP 2.6.5, 3.1.0, 3.1.5 | 3.4.6 | 3.4 end of life 1 Jun 2020 |
| CDP 7.1.1 to 7.1.5 | Not confirmed from Cloudera's published component lists | Check your parcel |
| CDP 7.1.6, 7.1.7, 7.1.8 | 3.5.5 | 3.5 end of life 1 Jun 2022 |
| CDP 7.1.9 | 3.8.1 | 3.8 still maintained upstream |
| Cloudera 7.3.1 | 3.8.1 | 3.8 still maintained upstream |
| Cloudera 7.3.2 | 3.8.5 | 3.8 still maintained upstream |
Cloudera builds carry Cloudera's own patches on top of the upstream version, so the upstream number is a starting point, not a verdict. For CDH and HDP, though, vendor patching stopped in 2022, so anything published after that is unpatched.
CVE-2023-44981 on ZooKeeper 3.4 and 3.5
CVE-2023-44981 is a SASL quorum peer authentication bypass, rated 9.1 Critical on NVD. An authentication ID without an instance part skips the check, and a rogue peer can then get full read-write access to the data tree. Apache fixed it in 3.7.2, 3.8.3 and 3.9.1. Every earlier line, including all of 3.4 and 3.5, is affected and was never fixed, because those lines were already end of life.
It was published on 11 October 2023, after the last CDH and HDP Limited Support window had closed. So no CDH or HDP ZooKeeper build carries a fix. It applies only when quorum SASL authentication is switched on (quorum.auth.enableSasl=true), so the first check on each ensemble is that setting. If it is off, this CVE does not apply, but the ensemble also has no authentication between quorum peers at all.
For CDP 7.1.7 and 7.1.8, which were still in support in October 2023 and bundle a 3.5.5-based build, check Cloudera's fixed-CVE list for your exact runtime build.
log4j 1.2.17 next to it
Upstream ZooKeeper 3.4.x, and 3.5.x up to 3.5.9, ship log4j 1.2.17. Expect to find log4j 1.x in the ZooKeeper library directory of these distributions and in many of the services around it. The log4j 1.2 CVEs, such as CVE-2019-17571 and CVE-2022-23305 (both 9.8 on NVD), each need a specific appender or component, and ZooKeeper's default logging configuration does not enable them. In practice they are scanner and audit findings rather than demonstrated default-configuration exploits, but they are findings you have to answer for.
What depends on that ZooKeeper ensemble
- HDFS high availability. Automatic NameNode failover adds a ZooKeeper quorum and the ZKFailoverController (ZKFC). ZooKeeper does the failure detection and active NameNode election.
- YARN ResourceManager HA. The ResourceManager embeds the ZooKeeper-based ActiveStandbyElector, and the ZooKeeper state store is the recommended store for an HA cluster.
- Apache HBase. A distributed HBase installation depends on a running ZooKeeper cluster, managed by HBase or external.
- Apache Hive. HiveServer2 dynamic service discovery registers each instance in ZooKeeper, and the ZooKeeper lock manager is used unless transactions move locking into the metastore.
That is why the ensemble cannot simply be swapped for a newer one on its own. A ZooKeeper upgrade changes the client libraries that these services were built and tested against. Our pages on ZooKeeper in Hadoop and ZooKeeper in HBase go through each dependency in detail, and ZooKeeper in CDH and HDP covers the distribution builds.
What end of life means for CDH and HDP customers
- No patches. No security fixes for any component, from HDFS and YARN to Impala, Hive, Spark and HBase.
- No escalation path. A production incident is yours to solve, with the community documentation and your own team.
- Audit findings. Unsupported software is a standing finding under most security frameworks, and scanners flag the bundled open source components individually.
- A shrinking skills pool. Fewer engineers each year have run CDH 5 or HDP 2 in production.
Your options
1. Upgrade to Cloudera on premises 7.1.9 or 7.3.2
This keeps you on the Cloudera platform with vendor support: 7.1.9 to October 2028, 7.3.2 to March 2032. Both bundle ZooKeeper 3.8, which is still maintained upstream. The work is real. CDH-to-CDP and HDP-to-CDP upgrades change component versions across the stack, and Sentry has been removed in CDP, so CDH authorization policies have to be migrated to Apache Ranger. Cloudera documents the upgrade from specific CDH and HDP releases; check where your release sits before you plan the hop.
2. Migrate to a cloud platform
Many estates use the end of CDH or HDP as the point to leave self-managed Hadoop entirely. The targets include Cloudera's own public cloud service, the managed Hadoop and Spark services of the major cloud providers, and lakehouse platforms such as Databricks, which is why Hadoop-to-Databricks migration is a common search. Each is a data and workload migration, not an upgrade: HDFS data moves to object storage, Hive and Impala SQL gets tested against a new engine, and HBase workloads need a separate answer.
3. Keep running with third-party patches while you plan
Neither route above finishes in a quarter for a large estate, and the cluster keeps running in the meantime. Third-party support can keep the most exposed layers patched during that period: the ZooKeeper ensemble first, then the data services that face users. This is a bridge. It reduces risk on a platform you are leaving, and it does not replace the migration.
The challenges of migrating off CDH and HDP
- The inventory is bigger than the cluster. Oozie workflows, edge-node scripts, JDBC clients pinned to old drivers, and Kerberos principals all have to move or be retired.
- HBase is the hardest workload. Real-time, low-latency operational tables have fewer like-for-like destinations than batch SQL analytics.
- Security models change. Sentry, Ranger and cloud IAM policies do not map one to one, so access control has to be reviewed again, not just copied.
- Both platforms run in parallel. For months the old cluster still serves production while the new one is validated, and it still needs patching.
Where OSSeva fits
OSSeva ships extended support for both distributions: CDH extended support and HDP extended support. That covers patched builds of the components these clusters run, starting with the ZooKeeper ensembles inside CDH, HDP and early CDP (with fixes for CVE-2023-44981 and the log4j 1.x exposure) and extending to HBase, Hive and HDFS and YARN. When you are ready to move to CDP, a cloud platform or a lakehouse, the same team plans and runs the migration.
Frequently asked questions
When did Cloudera CDH reach end of life?
The last CDH releases, 6.2 and 6.3, reached end of support in March 2022. Limited Support for eligible customers ran until 30 September 2022. CDH 5.14 to 5.16 ended in December 2020.
When did HDP reach end of life?
HDP 3.1 reached end of support in December 2021, with Limited Support until 30 June 2022. HDP 2.6 ended in December 2020.
What is the latest version of Cloudera?
For on-premises clusters, Cloudera 7.3.2, released in March 2026 and supported to March 2032. The latest Cloudera Manager is 7.13.2, also from March 2026.
Is Hadoop end of life?
No. Apache Hadoop is actively maintained: 3.5.0, the first stable release of the 3.5 line, came out on 2 April 2026. What is end of life is the CDH and HDP distributions and the old Hadoop versions they packaged.
Which ZooKeeper version does CDH use?
CDH 5 and CDH 6 bundle ZooKeeper 3.4.5, and HDP bundles 3.4.6. CDP 7.1.6 to 7.1.8 bundle 3.5.5, and 7.1.9 bundles 3.8.1.
Who acquired Cloudera?
Clayton, Dubilier & Rice and KKR, in a take-private deal completed on 8 October 2021. Earlier, Cloudera merged with Hortonworks, completing the merger on 3 January 2019.
Is Cloudera a competitor to Databricks?
They compete for many of the same analytics and data engineering workloads, and Databricks is one of the platforms CDH and HDP estates evaluate when they migrate. The right target depends on your workloads, especially HBase and SQL, not on the vendor.
Tags
Related articles
ZooKeeper Vulnerabilities by Version: CVEs in 3.4 to 3.9
September 29, 2026MigrationZooKeeper Alternatives: ZooKeeper vs etcd, Consul, KRaft and ClickHouse Keeper
September 29, 2026ComplianceWhy Your Scanner Flags the ZooKeeper Inside a Product You Bought, and How VEX Attestation Answers It
September 29, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.