End of life

Apache ZooKeeper 3.4 end of life

Apache ZooKeeper 3.4 reached end of life on 1 June 2020. The ZooKeeper community announced it on 9 April 2020, saying it would no longer accept patches, create releases or resolve CVEs on the 3.4 branch. The last release is 3.4.14, from 2 April 2019. 3.4 is still embedded in older Kafka, HBase and Hadoop estates. OSSeva ships patched 3.4 builds.

End of life
1 June 2020
Released
Nov 2011
Final release
3.4.14 (2 April 2019)
Successor
ZooKeeper 3.8 or 3.9

Date published by ZooKeeper 3.4 end-of-life announcement. We do not publish a lifecycle date we cannot source.

Last reviewed

What actually stops on 1 June 2020

  • Releases, patches and CVE fixes on the 3.4.x branch, as the announcement set out. 3.4.14 was the last.
  • Fixes for later advisories. CVE-2023-44981, a SASL quorum authentication bypass that NVD rates 9.1, affects every version before 3.7.2, including 3.4.
  • Fixes for the bundled libraries. 3.4.14 depends on log4j 1.2.17, which is affected by CVE-2019-17571 (rated 9.8) and has had no fixes since, and on Netty 3.10.6.

What actually breaks in the upgrade

The community's path went through 3.5

The end-of-life announcement gave the supported path as the latest 3.4.x, then the latest 3.5.x, then 3.6. Today the targets are 3.8.7 and 3.9.6, but a 3.4 ensemble should still pass through 3.5 on the way, with a rolling upgrade at each step.

Two settings stop a 3.5 node starting

From 3.5.5, a server that finds transaction logs but no snapshot refuses to start unless snapshot.trust.empty is set for that first start. 3.5 also restricts four-letter-word commands to an allow list in 4lw.commands.whitelist, which breaks monitoring that relies on stat or mntr.

Find the embedded copies first

Kafka releases up to 2.3.1 bundle a ZooKeeper 3.4 client (3.4.14 in 2.3.1), and Kafka 2.4.0 moved to 3.5.6. Check HBase, Hadoop, Solr and Storm dependencies too, because scanners will report the embedded 3.4 jar wherever it sits.

Your options, costed honestly

Including the ones that do not involve buying anything from us.

OptionWhat it isEffortCostOur view
Upgrade to 3.8 or 3.9Rolling upgrades through 3.5, with configuration changes at each step.WeeksEngineering timeThe destination for ensembles you control.
OSSeva patched 3.4 buildsSigned 3.4 builds with backported ZooKeeper fixes and patched bundled libraries.DaysSubscriptionFor ensembles tied to a product version that cannot move yet.
Replace ZooKeeperKafka to KRaft, or another coordination store.QuartersEngineering timeRight when the product above ZooKeeper is being upgraded anyway.
Stay on 3.4.14No community fixes since 2019.NoneZero nowSix years of advisories and a log4j 1.x dependency. Hard to defend in any audit.

What OSSeva does for Apache ZooKeeper 3.4

OSSeva patches this line

OSSeva ships patched, signed ZooKeeper 3.4 builds with backported fixes for ZooKeeper itself and patched bundled libraries, including the log4j 1.x and Netty 3 dependencies. They are available on the Patch, Assure and Operate tiers, and OSSeva engineers run the staged move to 3.8 or 3.9 when the products above it allow.

Apache ZooKeeper extended support

What your auditor will say

PCI DSS v4 Requirement 6.3.3

Every system component in the cardholder data environment needs its applicable security patches. A component with no upstream fix supply needs a patched source or a documented compensating control.

SOC 2 CC7.1

Auditors ask for evidence that production systems receive security fixes. A version past end of life fails that test unless another supplier ships the fixes and can show which CVEs they close.

Compliance library Every Apache ZooKeeper version and end-of-life date

Apache ZooKeeper 3.4: common questions

When did ZooKeeper 3.4 reach end of life?

On 1 June 2020. The ZooKeeper community announced the date on the user mailing list on 9 April 2020.

What is the last ZooKeeper 3.4 release?

3.4.14, released on 2 April 2019.

Can ZooKeeper 3.4 upgrade directly to 3.8?

Not in one step. The community's documented path is the latest 3.4.x to the latest 3.5.x, then onward one line at a time with rolling upgrades.

Is ZooKeeper 3.4 affected by recent CVEs?

Yes. CVE-2023-44981 affects all versions before 3.7.2, and the bundled log4j 1.2.17 is affected by CVE-2019-17571. The 2026 ZooKeeper CVEs are listed by NVD against 3.8 and 3.9 only.

Can I get security patches for ZooKeeper 3.4?

Yes. OSSeva ships patched, signed 3.4 builds on the Patch, Assure and Operate tiers.

Still running Apache ZooKeeper 3.4?

Tell us the versions and the estate size. We will tell you honestly whether to upgrade or to buy cover — and we say 'upgrade' more often than you would expect.