// Cloudera CDH extended support
Still running CDH 5 or CDH 6?
Support ended years ago. Patched components are available today.
Cloudera's support lifecycle policy ended CDH 5.14 to 5.16 in December 2020 and CDH 6.2 and 6.3 in March 2022, and limited support for eligible CDH 6 customers finished in September 2022. Every CDH release from 5.0 to 6.3 bundles ZooKeeper 3.4.5, from an upstream line that reached end of life in June 2020. OSSeva ships patched builds of the CDH components that carry the most exposure, ZooKeeper included, so the cluster stays supported while the exit is planned.
Trusted globally by enterprises




Why CDH clusters are still in production
CDH clusters tend to hold years of data and jobs that nobody wants to rewrite in a hurry.
Every exit is a platform move
Leaving CDH means a new distribution or a new data platform. Data, jobs, security policies and downstream consumers all move, and that work runs for quarters.
ZooKeeper 3.4.5 sits under everything
HDFS HA, YARN HA, HBase, HiveServer2 and Cloudera Search all coordinate through the same ensemble. The upstream 3.4 line never received a fix for CVE-2023-44981 and ships log4j 1.2.17. Cloudera's builds carry their own patches, so check the fixed-CVE list for your exact build.
Scanners read the version string
Scanners match zookeeper-3.4.5 and the CDH component versions against public advisories. Without patched builds and a written assessment, each finding has to be argued by hand.
The dates that matter
2019-08
End of support for CDH 5.8 and earlier.
2020-06-01
ZooKeeper 3.4 end of life upstream. Every CDH release bundles 3.4.5.
2020-12
End of support for CDH 5.14, 5.15 and 5.16.
2021-08
End of support for CDH 6.0.
2021-12
End of support for CDH 6.1.
2022-03
End of support for CDH 6.2 and 6.3.
2022-09-30
Limited support for eligible CDH 6.2 and 6.3 customers ends.
What OSSeva delivers
Patched CDH components
Signed builds with backported security fixes for HDFS, YARN, HBase and Hive on CDH 5 and 6, matched to the CDH release you run so the cluster keeps its version and configuration.
Patched ZooKeeper 3.4.5
The bundled ensemble, patched and dropped in with configuration and data unchanged, plus VEX statements for the findings your scanner raises against it.
Migration off CDH
A migration plan per workload to a current distribution, upstream Apache releases or a cloud platform, carried out with your team while the patched cluster keeps running.
Your options, compared
| Option | What you get | Trade-off |
|---|---|---|
| Upgrade to a current commercial distribution | Vendor support for current Hadoop components | A full platform upgrade and a new subscription. |
| Migrate to a cloud data platform | Managed storage and compute | Data movement and job rewrites across several quarters. |
| OSSeva extended support | Patched CDH components and ZooKeeper today, and help with the move | A subscription while CDH stays in production. |
| Stay on unsupported CDH | Nothing | Findings accumulate on the cluster that holds the most data. |
End-of-support dates from Cloudera's support lifecycle policy. Bundled ZooKeeper versions from Cloudera's CDH 5 and CDH 6 packaging documentation. ZooKeeper advisories from zookeeper.apache.org/security.
Frequently asked questions
When did CDH reach end of life?
According to Cloudera's support lifecycle policy, CDH 5.14 to 5.16 ended in December 2020, CDH 6.0 in August 2021, 6.1 in December 2021, and 6.2 and 6.3 in March 2022. Limited support for eligible CDH 6.2 and 6.3 customers ran to 30 September 2022.
Which ZooKeeper version does CDH use?
ZooKeeper 3.4.5 with Cloudera patches, in every release from CDH 5.0 to 6.3. The upstream 3.4 line reached end of life on 1 June 2020.
Can we still get Cloudera CDH support?
CDH is past every date in the vendor's lifecycle policy. OSSeva supports CDH 5 and 6 clusters as they are, with patched components and ZooKeeper builds shipping now, until you move.
Do we have to upgrade CDH to get patches?
No. Patched builds match the CDH release you run, so the cluster keeps its current version and configuration.
Which support tier fits a CDH cluster?
Patch covers signed builds with backported fixes. Assure adds an ensemble audit and an attestation package for auditors. Operate adds 24/7 monitoring and named engineers.
Keep CDH patched while the exit is planned.
Start with Patch today. Add Assure or Operate when the cluster needs them.