// What runs on ZooKeeper / hive
Does Apache Hive use ZooKeeper?
Used for HA, discovery and locksOften. HiveServer2 uses ZooKeeper for dynamic service discovery and active/passive high availability, and ZooKeeperHiveLockManager is the default lock manager when concurrency is enabled without ACID transactions. With DbTxnManager, locks move into the metastore database instead.
Trusted globally by enterprises




What Apache Hive uses ZooKeeper for
- HiveServer2 dynamic service discovery: each instance registers itself, and JDBC clients connect through the ZooKeeper namespace.
- HiveServer2 active/passive high availability.
- Table and partition locks through ZooKeeperHiveLockManager when not using ACID transactions.
- Delegation token store, LLAP registry and privilege synchronisation leader election.
Which ZooKeeper version ships with Apache Hive
From the zookeeper.version property in pom.xml at each release tag.
| Release | ZooKeeper | ZooKeeper line status | Open ZooKeeper CVEs |
|---|---|---|---|
| Hive 3.1.3 | 3.4.6 | End of life since 1 June 2020Bundles log4j 1.2.17 | 3 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line |
| Hive 4.2.1 | 3.8.4 | Supported (latest 3.8.7) | 5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993) |
CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.
What ZooKeeper 3.4.6 is exposed to
CVE-2018-8012 · CVSS 7.5 · fixed in 3.4.10, 3.5.4-beta
No authentication or authorisation on servers joining the quorum, so a rogue peer can push changes to the leader.
CVE-2019-0201 · CVSS 5.9 · fixed in 3.4.14, 3.5.5
getACL() performs no permission check and exposes unsalted digest authentication hashes.
CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1
SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.
Find the ZooKeeper Hive is using
grep -A1 -E 'hive.zookeeper.quorum|hive.server2.support.dynamic.service.discovery|hive.lock.manager' conf/hive-site.xml ls lib/ | grep -E '^zookeeper-[0-9]'
Can Apache Hive run without ZooKeeper?
Yes, for a single HiveServer2 with ACID transactions (DbTxnManager), which keeps locks in the metastore. Discovery, HA and the ZooKeeper lock manager all need it.
Hive 3.x reached end of life on 8 October 2024 and 2.x on 20 May 2024. Hive 4.2.1 is current.
Your options
Upgrade to Hive 4
Hive 4.2 bundles ZooKeeper 3.8.4. The upgrade usually rides on a Hadoop platform upgrade.
Patch the ensemble
OSSeva patches the ZooKeeper ensemble shared by Hive, HBase and HDFS HA, which is usually the oldest shared component in the estate.
Most teams buy this at the product level: keep the Apache Hive estate supported, including the ZooKeeper under it. See Hive extended support.
Frequently asked questions
Does Hive 3.1 use an end-of-life ZooKeeper?
Hive 3.1.3 bundles ZooKeeper 3.4.6, and the 3.4 line reached end of life on 1 June 2020. Hive 3.x itself reached end of life on 8 October 2024.
Keep Apache Hive and the ZooKeeper under it supported.
Send us your versions; we reply with coverage, exposure and a plan within five working days.