OSSEVA FOR APACHE HBASE

HBase 2.4 is end of life. Your regions are still serving.

The last 2.4 release, 2.4.18, shipped on 25 May 2024, and the project marked the line end of life that July. HBase 1.x ended with 1.7.2 in August 2022. OSSeva ships patched builds for both lines today, and for the ZooKeeper they run on.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why now

Only 2.5, 2.6 and 3.0 still get fixes

The HBase reference guide lists 2.5 and 2.6 as the active release lines, and 3.0.0 shipped on 5 August 2026. Everything older is end of maintenance: 2.4 since July 2024, 1.x since September 2022, 2.3 since March 2022 and 2.2 since October 2021. HBase clusters sit under long-lived applications, so the installed base runs well behind that line.

The hidden ZooKeeper time bomb

Every distributed HBase cluster depends on ZooKeeper, and HBase 3.0 still needs it on the server side. HBase 1.7.2 and 2.2.7 bundle ZooKeeper 3.4.10, from a line that reached end of life on 1 June 2020 and is exposed to CVE-2019-0201. HBase 2.3.7 bundles 3.5.7, which still ships log4j 1.2.17. When HBase manages its own ensemble, that bundled version is the server running in production. Few teams have ever checked it.

An HBase upgrade is rarely just HBase

The reference guide keeps a separate Hadoop compatibility matrix for each HBase line and recommends Hadoop 3. A cluster on HBase 1.x or 2.2 usually sits on Hadoop 2, so the HBase upgrade turns into a Hadoop upgrade. Inside a CDH or HDP cluster it turns into a platform migration. Patched builds keep the cluster supported while that decision is made.

Versions covered

All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.

VersionStatusActive CVEs
1.7.x(Community EOL Sep 2022 — OSSeva patched)EOLClean
2.2.x(Community EOL Oct 2021 — OSSeva patched)EOLClean
2.3.x(Community EOL Mar 2022 — OSSeva patched)EOLClean
2.4.x(Community EOL Jul 2024 — OSSeva patched)EOLClean
2.5.x(Upstream maintained)ExtendedClean
2.6.x(Upstream maintained)ExtendedClean
3.0.x(Released 5 Aug 2026)CurrentClean

What you get

Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.

OSSeva Patch

Patched, signed HBase 1.7, 2.2, 2.3 and 2.4 builds, bundled ZooKeeper included.

  • Security backports for 1.7, 2.2, 2.3 and 2.4, region data untouched
  • Bundled ZooKeeper patched in the same build
  • Transitive dependency patching (Netty, Jetty, Jackson, log4j)
  • Maven / Docker / tarball delivery
  • Signed artifacts (GPG) and VEX statements for scanner findings
  • Cluster and ensemble security audit
  • 24/7 managed operations
Get started →
Most popular

OSSeva Assure

Patch plus a cluster audit covering HBase, Hadoop and ZooKeeper together.

  • Everything in Patch
  • Master, region server and ZooKeeper quorum review
  • Kerberos, ACL and coprocessor exposure audit
  • Hadoop and ZooKeeper version map for every HBase cluster
  • SOC 2 / HIPAA attestation package with VEX for auditors
  • Upgrade plan to 2.5, 2.6 or 3.0
  • 24/7 managed operations
Get started →

OSSeva Operate

Full MSP: 24/7 HBase monitoring, 15-min SLA, named engineers.

  • Everything in Assure
  • 24/7 region, compaction and RPC latency monitoring
  • 15-minute P1 incident response SLA
  • Named senior HBase engineer
  • Region balancing, snapshot and replication management
  • Rolling upgrade execution with the ZooKeeper quorum preserved
  • Quarterly capacity and hotspot reviews
Get started →

All tiers priced per cluster/application — not per core. Contact for pricing →

How it installs

OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.

Check the HBase version and the ZooKeeper under itbash
# HBase version on this node
hbase version 2>/dev/null | head -1

# ZooKeeper jar bundled with this HBase
ls $HBASE_HOME/lib/ | grep -E '^zookeeper-[0-9]'

# Is HBase running its own ensemble from that jar?
grep HBASE_MANAGES_ZK $HBASE_HOME/conf/hbase-env.sh

# Version the ensemble is actually running
echo srvr | nc zk1.internal 2181 | head -1
Maven: OSSeva HBasexml
<dependency>
  <groupId>io.osseva.hbase</groupId>
  <artifactId>hbase-shaded-client</artifactId>
  <version>2.4.18-osseva-1</version>
</dependency>

Migrate from Unsupported HBase 1.x and 2.4 clusters

OSSeva ships patched builds on the HBase line you already run, so region layout, coprocessors and client jars stay as they are, and the bundled ZooKeeper is patched in the same build. When the cluster moves to 2.5, 2.6 or 3.0, OSSeva plans and runs the rolling upgrade with the Hadoop and ZooKeeper layers kept in step.

↗

Pricing model

OSSeva for Apache HBase is priced per cluster, not per region server or per table.

Compliance library

📄SOC 2 compliance evidence package
Request →
📄Sample Audit Narrative
Request →
📄Pen-Test Report Summary
Request →
📄HIPAA Technical Safeguard Matrix
Request →

Frequently asked questions

Is HBase 2.4 end of life?

Yes. HBase 2.4.18, released on 25 May 2024, was announced as the last patch release of the 2.4 line, and the project marked 2.4 end of life in July 2024. The reference guide lists 2.5 and 2.6 as the active lines, and 3.0.0 was released on 5 August 2026.

When did HBase 1.x reach end of life?

HBase 1.7.2, released on 9 August 2022, was the last release of the 1.x line, and the project marked 1.x end of life in September 2022. HBase 1.7.2 bundles ZooKeeper 3.4.10.

Does HBase 3.0 still need ZooKeeper?

Yes, on the server side. HBase 3.0 makes RpcConnectionRegistry the default for clients, so applications no longer need ZooKeeper to find hbase:meta, but masters and region servers still coordinate through it. The work to remove ZooKeeper from client connections is targeted at HBase 4.

Which ZooKeeper version does my HBase bundle?

It depends on the release. HBase 1.7.2 and 2.2.7 bundle ZooKeeper 3.4.10, 2.3.7 bundles 3.5.7, 2.4.18 bundles 3.8.4, and 2.5.15, 2.6.6 and 3.0.0 bundle 3.8.6. The 3.4 and 3.5 lines are past community end of life. OSSeva patches the bundled ZooKeeper together with HBase.

Can OSSeva patch HBase without an upgrade?

Yes. OSSeva ships patched builds on 1.7, 2.2, 2.3 and 2.4, so the region layout, table schemas, coprocessors and client jars stay as they are. Patched builds go in through a normal rolling restart. Start with Patch, and talk to an engineer when the move to 2.5, 2.6 or 3.0 is on the table.

Ready to get Apache HBase patched and supported?

Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.