// What runs on ZooKeeper / cloudera-cdh-hdp

Does Cloudera CDH, HDP and CDP use ZooKeeper?

Bundled in every release

Every Cloudera distribution ships its own ZooKeeper build, because HDFS HA, YARN HA, HBase, Hive and Solr all use it. CDH 5 and 6 bundle ZooKeeper 3.4.5, HDP 2.6 and 3.1 bundle 3.4.6, and CDP Private Cloud Base 7.1.6 to 7.1.8 bundle 3.5.5. All of those ZooKeeper lines are past community end of life.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Cloudera CDH, HDP and CDP uses ZooKeeper for

  • HDFS NameNode HA (ZKFC) and YARN ResourceManager HA.
  • HBase master election and region server tracking.
  • HiveServer2 discovery and HA, and Solr (Cloudera Search) cluster state.

Which ZooKeeper version ships with Cloudera CDH, HDP and CDP

From Cloudera's published component-version and packaging lists for each release. Cloudera builds carry vendor patches on top of the upstream version, so the upstream CVE ranges are a starting point for review, not a final answer.

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
CDH 5 (5.0 to 5.16)CDH end of support: December 2020 for 5.14 to 5.163.4.5End of life since 1 June 2020Bundles log4j 1.2.173 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line
CDH 6 (6.0 to 6.3)CDH 6.2 and 6.3 end of support: March 20223.4.5End of life since 1 June 2020Bundles log4j 1.2.173 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line
HDP 2.6.5HDP 2.6 end of support: December 20203.4.6End of life since 1 June 2020Bundles log4j 1.2.173 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line
HDP 3.1.0 and 3.1.5HDP 3.1 end of support: December 20213.4.6End of life since 1 June 2020Bundles log4j 1.2.173 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line
CDP 7.1.6 to 7.1.87.1.8 end of support: August 20243.5.5End of life since 1 June 2022Bundles log4j 1.2.171 (CVE-2023-44981)2026 advisories not assessed for this line
CDP 7.1.9 and 7.3.17.1.9 supported to October 20283.8.1Supported (latest 3.8.7)7 (CVE-2023-44981, CVE-2024-23944, CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)
CDP 7.3.2Supported to March 20323.8.5Supported (latest 3.8.7)5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.4.5 is exposed to

CVE-2018-8012 · CVSS 7.5 · fixed in 3.4.10, 3.5.4-beta

No authentication or authorisation on servers joining the quorum, so a rogue peer can push changes to the leader.

CVE-2019-0201 · CVSS 5.9 · fixed in 3.4.14, 3.5.5

getACL() performs no permission check and exposes unsalted digest authentication hashes.

CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1

SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.

Find the ZooKeeper build in a CDH or HDP cluster

# CDH (parcels)
ls /opt/cloudera/parcels/CDH/jars/ | grep -E '^zookeeper-[0-9]'

# HDP
ls /usr/hdp/current/zookeeper-server/ | grep -E '^zookeeper-[0-9]'

echo srvr | nc zk1.internal 2181 | head -1

Can Cloudera CDH, HDP and CDP run without ZooKeeper?

No. ZooKeeper is a core service in every CDH, HDP and CDP cluster.

CDH 6.3 support ended in March 2022, CDH 5.16 in December 2020, HDP 3.1 in December 2021 and HDP 2.6 in December 2020.

Your options

Upgrade to CDP 7.1.9 or 7.3.2

The in-place Cloudera path. 7.1.9 is supported to October 2028 and 7.3.2 to March 2032, and both bundle ZooKeeper 3.8.

Migrate off Hadoop

Cloud data platforms are the other common destination. It is a multi-quarter programme for most estates.

Keep running, patched

OSSeva ships patched builds for the components these clusters run, from the shared ZooKeeper to HBase, Hive, HDFS and YARN, to cover the time the platform decision takes.

Most teams buy this at the product level: keep the Cloudera CDH, HDP and CDP estate supported, including the ZooKeeper under it. See CDH extended support.

Frequently asked questions

Which ZooKeeper version is in CDH 6?

CDH 6.0 through 6.3 bundle ZooKeeper 3.4.5 with Cloudera patches. The upstream 3.4 line reached end of life on 1 June 2020.

Which ZooKeeper version is in HDP 3.1?

HDP 3.1.0 and 3.1.5 bundle ZooKeeper 3.4.6 with Hortonworks patches.

When did CDH and HDP reach end of support?

CDH 5.14 to 5.16 in December 2020, CDH 6.2 and 6.3 in March 2022, HDP 2.6 in December 2020 and HDP 3.1 in December 2021.

Keep Cloudera CDH, HDP and CDP and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.