OSSEVA FOR APACHE HIVE
Hive 3 reached end of life on 8 October 2024.
Hive 1.x ended on 11 April 2024 and 2.x on 20 May 2024. Only the 4.x line gets releases now. OSSeva ships patched builds for all three end-of-life lines today.
Trusted globally by enterprises




Why now
Three Hive lines ended within six months
The Hive project announced end of life for 1.x on 11 April 2024, 2.x on 20 May 2024 and 3.x on 8 October 2024. The last 2.x release was 2.3.10 on 9 May 2024, and the last 3.x release was 3.1.3 on 8 April 2022. Current development is on 4.x, with 4.2.1 released on 24 August 2026.
Hive 4 is a platform upgrade, not a jar swap
Hive sits between the metastore database, HDFS or object storage, the execution engine, and every BI tool that connects over JDBC. Moving to Hive 4 means a metastore schema upgrade, new client drivers and, in most clusters, a newer Hadoop underneath. In CDH and HDP clusters it is part of the wider platform decision, and that decision takes time.
The hidden ZooKeeper time bomb
HiveServer2 uses ZooKeeper for service discovery and active/passive high availability, and ZooKeeperHiveLockManager is the default lock manager when concurrency is on without ACID transactions. Hive 1.2.2, 2.3.10 and 3.1.3 all bundle ZooKeeper 3.4.6, from a line that reached end of life on 1 June 2020 and is exposed to CVE-2018-8012 and CVE-2019-0201. The ensemble is usually shared with HBase and HDFS failover, so one old quorum carries the whole platform.
Versions covered
All versions below receive active CVE patches from OSSeva. Version numbers in monospace are exact release identifiers.
| Version | Status | Active CVEs |
|---|---|---|
| 1.2.x(Community EOL 11 Apr 2024 — OSSeva patched) | EOL | Clean |
| 2.3.x(Community EOL 20 May 2024 — OSSeva patched) | EOL | Clean |
| 3.1.x(Community EOL 8 Oct 2024 — OSSeva patched) | EOL | Clean |
| 4.0.x(Superseded by 4.1 and 4.2) | Extended | Clean |
| 4.1.x(Superseded by 4.2) | Extended | Clean |
| 4.2.x(4.2.1 released 24 Aug 2026) | Current | Clean |
What you get
Three tiers — pick the level of engagement that matches your team's operational needs and compliance requirements.
OSSeva Patch
Patched, signed Hive 1.2, 2.3 and 3.1 builds with the metastore schema unchanged.
- Security backports for 1.2, 2.3 and 3.1, no metastore schema change
- Bundled ZooKeeper and Curator patched in the same build
- Transitive dependency patching (Jetty, Jackson, Netty, log4j)
- Maven / tarball / RPM delivery, JDBC driver included
- Signed artifacts (GPG) and VEX statements for scanner findings
- HiveServer2 and metastore security audit
- 24/7 managed operations
OSSeva Assure
Patch plus a HiveServer2, metastore and ZooKeeper audit.
- Everything in Patch
- HiveServer2 discovery, HA and lock manager review
- Authentication, authorisation and UDF exposure audit
- Map of every JDBC client and BI tool connecting to HiveServer2
- SOC 2 / HIPAA attestation package with VEX for auditors
- Upgrade plan to Hive 4.2, including the metastore schema
- 24/7 managed operations
OSSeva Operate
Full MSP: 24/7 HiveServer2 and metastore monitoring, 15-min SLA.
- Everything in Assure
- 24/7 HiveServer2 session, query and metastore monitoring
- 15-minute P1 incident response SLA
- Named senior Hive engineer
- Metastore database backup and compaction management
- Hive 4 upgrade execution with metastore schema migration
- Quarterly query performance reviews
All tiers priced per cluster/application — not per core. Contact for pricing →
How it installs
OSSeva artifacts arrive via your existing package infrastructure. Pull the patched version the same way you pull upstream today — just from the OSSeva registry.
# Hive version on this node
hive --version | head -1
# Version reported by a running HiveServer2 (Hive 2.1 and later)
beeline -u "jdbc:hive2://hs2.internal:10000/default" -e "select version();"
# ZooKeeper jar bundled with this Hive
ls $HIVE_HOME/lib/ | grep -E '^zookeeper-[0-9]'
# Where HiveServer2 registers, and which lock and transaction managers are active
grep -A1 -E 'hive.zookeeper.quorum|hive.server2.support.dynamic.service.discovery|hive.lock.manager|hive.txn.manager' \
$HIVE_HOME/conf/hive-site.xml
# HiveServer2 instances registered in ZooKeeper (default namespace)
zkCli.sh -server zk1.internal:2181 ls /hiveserver2<dependency>
<groupId>io.osseva.hive</groupId>
<artifactId>hive-jdbc</artifactId>
<version>3.1.3-osseva-1</version>
</dependency>Migrate from Unsupported Hive 2 and 3 warehouses
OSSeva ships patched builds on the Hive line you already run, so the metastore schema, table definitions, UDFs and JDBC connections stay as they are. The bundled ZooKeeper is patched in the same build. When the move to Hive 4.2 is due, OSSeva plans and runs it, metastore schema upgrade included.
Pricing model
OSSeva for Apache Hive is priced per cluster, not per query, user or table.
Frequently asked questions
Is Hive 3 end of life?
Yes. The Hive project announced end of life for the 3.x line on 8 October 2024. The last 3.x release was 3.1.3, on 8 April 2022. Hive 4.2.1, released on 24 August 2026, is the current release.
Is Hive 2 end of life?
Yes. Hive 2.x reached end of life on 20 May 2024, eleven days after its final release, 2.3.10, on 9 May 2024. Hive 1.x reached end of life on 11 April 2024.
Does Hive use ZooKeeper?
Often. HiveServer2 uses ZooKeeper for dynamic service discovery and active/passive high availability, and ZooKeeperHiveLockManager is the default lock manager when concurrency is enabled without ACID transactions. The delegation token store and the LLAP registry can use it too. With DbTxnManager, locks move into the metastore database instead.
Can we keep running Hive 3 and stay supported?
Yes. OSSeva ships patched Hive 3.1 builds today, with the same metastore schema and client protocol, so BI tools and ETL jobs keep working unchanged. The bundled ZooKeeper 3.4.6 is patched in the same build. Start with Patch, and plan the move to Hive 4.2 on your own timetable.
Which Hive version should we upgrade to?
Hive 4.2, the current line. Hive 4.2.1 bundles ZooKeeper 3.8.4. The upgrade usually rides on a Hadoop platform upgrade, so the Assure tier maps the metastore, execution engine and every connecting client before any change is made.
Ready to get Apache Hive patched and supported?
Start with a 45-minute discovery call. We confirm your version coverage, scope the engagement, and have you onboarded within your first quarter.