// What runs on ZooKeeper / cloudera-cdh-hdp
Does Cloudera CDH, HDP and CDP use ZooKeeper?
Bundled in every releaseEvery Cloudera distribution ships its own ZooKeeper build, because HDFS HA, YARN HA, HBase, Hive and Solr all use it. CDH 5 and 6 bundle ZooKeeper 3.4.5, HDP 2.6 and 3.1 bundle 3.4.6, and CDP Private Cloud Base 7.1.6 to 7.1.8 bundle 3.5.5. All of those ZooKeeper lines are past community end of life.
Trusted globally by enterprises




What Cloudera CDH, HDP and CDP uses ZooKeeper for
- HDFS NameNode HA (ZKFC) and YARN ResourceManager HA.
- HBase master election and region server tracking.
- HiveServer2 discovery and HA, and Solr (Cloudera Search) cluster state.
Which ZooKeeper version ships with Cloudera CDH, HDP and CDP
From Cloudera's published component-version and packaging lists for each release. Cloudera builds carry vendor patches on top of the upstream version, so the upstream CVE ranges are a starting point for review, not a final answer.
| Release | ZooKeeper | ZooKeeper line status | Open ZooKeeper CVEs |
|---|---|---|---|
| CDH 5 (5.0 to 5.16)CDH end of support: December 2020 for 5.14 to 5.16 | 3.4.5 | End of life since 1 June 2020Bundles log4j 1.2.17 | 3 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line |
| CDH 6 (6.0 to 6.3)CDH 6.2 and 6.3 end of support: March 2022 | 3.4.5 | End of life since 1 June 2020Bundles log4j 1.2.17 | 3 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line |
| HDP 2.6.5HDP 2.6 end of support: December 2020 | 3.4.6 | End of life since 1 June 2020Bundles log4j 1.2.17 | 3 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line |
| HDP 3.1.0 and 3.1.5HDP 3.1 end of support: December 2021 | 3.4.6 | End of life since 1 June 2020Bundles log4j 1.2.17 | 3 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line |
| CDP 7.1.6 to 7.1.87.1.8 end of support: August 2024 | 3.5.5 | End of life since 1 June 2022Bundles log4j 1.2.17 | 1 (CVE-2023-44981)2026 advisories not assessed for this line |
| CDP 7.1.9 and 7.3.17.1.9 supported to October 2028 | 3.8.1 | Supported (latest 3.8.7) | 7 (CVE-2023-44981, CVE-2024-23944, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
| CDP 7.3.2Supported to March 2032 | 3.8.5 | Supported (latest 3.8.7) | 5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.
What ZooKeeper 3.4.5 is exposed to
CVE-2018-8012 · CVSS 7.5 · fixed in 3.4.10, 3.5.4-beta
No authentication or authorisation on servers joining the quorum, so a rogue peer can push changes to the leader.
CVE-2019-0201 · CVSS 5.9 · fixed in 3.4.14, 3.5.5
getACL() performs no permission check and exposes unsalted digest authentication hashes.
CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1
SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.
Find the ZooKeeper build in a CDH or HDP cluster
# CDH (parcels) ls /opt/cloudera/parcels/CDH/jars/ | grep -E '^zookeeper-[0-9]' # HDP ls /usr/hdp/current/zookeeper-server/ | grep -E '^zookeeper-[0-9]' echo srvr | nc zk1.internal 2181 | head -1
Can Cloudera CDH, HDP and CDP run without ZooKeeper?
No. ZooKeeper is a core service in every CDH, HDP and CDP cluster.
CDH 6.3 support ended in March 2022, CDH 5.16 in December 2020, HDP 3.1 in December 2021 and HDP 2.6 in December 2020.
Your options
Upgrade to CDP 7.1.9 or 7.3.2
The in-place Cloudera path. 7.1.9 is supported to October 2028 and 7.3.2 to March 2032, and both bundle ZooKeeper 3.8.
Migrate off Hadoop
Cloud data platforms are the other common destination. It is a multi-quarter programme for most estates.
Keep running, patched
OSSeva ships patched builds for the components these clusters run, from the shared ZooKeeper to HBase, Hive, HDFS and YARN, to cover the time the platform decision takes.
Most teams buy this at the product level: keep the Cloudera CDH, HDP and CDP estate supported, including the ZooKeeper under it. See CDH extended support.
Frequently asked questions
Which ZooKeeper version is in CDH 6?
CDH 6.0 through 6.3 bundle ZooKeeper 3.4.5 with Cloudera patches. The upstream 3.4 line reached end of life on 1 June 2020.
Which ZooKeeper version is in HDP 3.1?
HDP 3.1.0 and 3.1.5 bundle ZooKeeper 3.4.6 with Hortonworks patches.
When did CDH and HDP reach end of support?
CDH 5.14 to 5.16 in December 2020, CDH 6.2 and 6.3 in March 2022, HDP 2.6 in December 2020 and HDP 3.1 in December 2021.
Keep Cloudera CDH, HDP and CDP and the ZooKeeper under it supported.
Send us your versions; we reply with coverage, exposure and a plan within five working days.