// What runs on ZooKeeper / hive

Does Apache Hive use ZooKeeper?

Used for HA, discovery and locks

Often. HiveServer2 uses ZooKeeper for dynamic service discovery and active/passive high availability, and ZooKeeperHiveLockManager is the default lock manager when concurrency is enabled without ACID transactions. With DbTxnManager, locks move into the metastore database instead.

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

What Apache Hive uses ZooKeeper for

  • HiveServer2 dynamic service discovery: each instance registers itself, and JDBC clients connect through the ZooKeeper namespace.
  • HiveServer2 active/passive high availability.
  • Table and partition locks through ZooKeeperHiveLockManager when not using ACID transactions.
  • Delegation token store, LLAP registry and privilege synchronisation leader election.

Which ZooKeeper version ships with Apache Hive

From the zookeeper.version property in pom.xml at each release tag.

ReleaseZooKeeperZooKeeper line statusOpen ZooKeeper CVEs
Hive 3.1.33.4.6End of life since 1 June 2020Bundles log4j 1.2.173 (CVE-2018-8012, CVE-2019-0201, CVE-2023-44981)2026 advisories not assessed for this line
Hive 4.2.13.8.4Supported (latest 3.8.7)5 (CVE-2026-24281, CVE-2026-24308, CVE-2026-59739, CVE-2026-59969, CVE-2026-79993)

CVE counts are ZooKeeper's own advisories matched against the upstream version. The Apache ZooKeeper project does not assess end-of-life lines against new advisories, so "not assessed" means unknown, not safe.

What ZooKeeper 3.4.6 is exposed to

CVE-2018-8012 · CVSS 7.5 · fixed in 3.4.10, 3.5.4-beta

No authentication or authorisation on servers joining the quorum, so a rogue peer can push changes to the leader.

CVE-2019-0201 · CVSS 5.9 · fixed in 3.4.14, 3.5.5

getACL() performs no permission check and exposes unsalted digest authentication hashes.

CVE-2023-44981 · CVSS 9.1 · fixed in 3.7.2, 3.8.3, 3.9.1

SASL quorum peer authentication bypass, giving full read-write access to the data tree. Applies when quorum.auth.enableSasl=true.

Find the ZooKeeper Hive is using

grep -A1 -E 'hive.zookeeper.quorum|hive.server2.support.dynamic.service.discovery|hive.lock.manager' conf/hive-site.xml

ls lib/ | grep -E '^zookeeper-[0-9]'

Can Apache Hive run without ZooKeeper?

Yes, for a single HiveServer2 with ACID transactions (DbTxnManager), which keeps locks in the metastore. Discovery, HA and the ZooKeeper lock manager all need it.

Hive 3.x reached end of life on 8 October 2024 and 2.x on 20 May 2024. Hive 4.2.1 is current.

Your options

Upgrade to Hive 4

Hive 4.2 bundles ZooKeeper 3.8.4. The upgrade usually rides on a Hadoop platform upgrade.

Patch the ensemble

OSSeva patches the ZooKeeper ensemble shared by Hive, HBase and HDFS HA, which is usually the oldest shared component in the estate.

Most teams buy this at the product level: keep the Apache Hive estate supported, including the ZooKeeper under it. See Hive extended support.

Frequently asked questions

Does Hive 3.1 use an end-of-life ZooKeeper?

Hive 3.1.3 bundles ZooKeeper 3.4.6, and the 3.4 line reached end of life on 1 June 2020. Hive 3.x itself reached end of life on 8 October 2024.

Keep Apache Hive and the ZooKeeper under it supported.

Send us your versions; we reply with coverage, exposure and a plan within five working days.