Enhancements
Info
This section consists of the enhancements introduced in this release.
Ambari
JIRA ID | Apache ID | Description |
|---|---|---|
ODP-5386 | Updated hbase.short.version to 2.5 as HBase was downgraded | |
ODP-5386 | Matched Phoenix-HBase version with ODP stack | |
ODP-5386 | Matched HBase version with ODP stack | |
ODP-5355 | Updated Ambari metainfo with ODP version info | |
ODP-5269 | Added security util to the older Ambari release | |
ODP-5266 | Added Hadoop-common & Zookeeper version to ODP 3.2.3 stack | |
OSV-8148 | Excluded json-smart from Ambari Infra Assembly to fix CVE-2023-1370 | |
OSV-8104 | Bumped AWS Java SDK to 1.12.791 to fix Jackson CBOR CVE | |
OSV-8192 | Bumped PostgreSQL driver to 42.7.8 to fix CVE | |
OSV-8147 | Bumped Logback to 1.2.13 to fix CVE | |
OSV-8214 | Bumped YamlBeans to 1.77 to fix CVE | |
OSV-8100 | Bumped H2 Database to 2.4.240 to fix CVE | |
OSV-8102 | Bumped Nimbus JOSE JWT to 9.37.2 to fix CVE | |
OSV-8189 | Bumped Netty to 4.1.127.Final to fix CVE | |
OSV-8037 | Bumped Flume NG Core to 1.11.0 to resolve Jettison CVEs | |
OSV-8479 | Bumped Ehcache to 2.10.9.2 to fix CVE | |
OSV-8178 | Bumped Jackson to 2.16.1 to fix CVE | |
OSV-8213 | Bumped Spring 5.3.26 & Spring Security 5.7.11 to fix CVEs | |
OSV-8216 | Bumped Guava to 32.0.1-jre to fix CVE | |
ODP-5039 | Backported security_credential_helper to Python 2 | |
ODP-4683-addendum | Restored SSL configs for MirrorMaker2 | |
ODP-4683 / ODP-4568 | Enhanced MirrorMaker2 to support Multi-Topology, mm2-env, and JAAS integration (3.0 & 3.3 stack) | |
ODP-4857 | Added Python2 compatibility for Druid scripts | |
ODP-4857 | Added ranger.jpa.jdbc.preferredtestquery in ranger-admin-site.xml for stack 3.0 | |
ODP-4637 | Updated Zeppelin version for stack 3.0 | |
ODP-4857 | Added ranger.jpa.jdbc.preferredtestquery in ranger-admin-site.xml for ODP 3.3+ | |
ODP-4725-addendum | Added default hive.perflogger.log.level=INFO | |
ODP-4725 | Fixed log4j2 warnings for unresolved hive.perflogger.log.level | |
ODP-4792 | Improved MirrorMaker service labels for Kafka2 | |
ODP-4592 | Added default Hive keystore password value | |
ODP-4637 | Updated Zeppelin version | |
AMBARI-26519 | Added check for public/local setup during first initialization | |
ODP-3611 | Added default proxy user configuration for Hue | |
ODP-4294 | Added Oozie SSL properties by default to fix exposure | |
ODP-3396 | Updated udp_preference_limit and default kdc_timeout for HA | |
ODP-1272 | Created separate profile to build only required Ambari RPMs | |
ODP-4349 | AMBARI-25952 | Bumped Spring Security Core from 5.7.2 to 5.7.8 |
ODP-4349 | AMBARI-25953 | Upgraded PostgreSQL from 42.2.2 to 42.3.8 |
ODP-4349 | AMBARI-25986 | Upgraded Ambari Hadoop dependency versions |
ODP-4349 | AMBARI-26184 | Resolved SnakeYAML 1.12 CVE |
ODP-4349 | AMBARI-26184 | Added ZooKeeper Admin server link |
ODP-4349 | AMBARI-26270 | Added HiveServer2 web UI quicklink |
ODP-4349 | AMBARI-24976 | Added Ozone as a filesystem service |
ODP-4349 | AMBARI-26012 | Documented procedure for reporting security issues |
ODP-4147 | Added SSL properties in hbase-site.xml | |
ODP-4151 | Added HDFS user to authorize Ozone Ranger Solr audit requests | |
ODP-4153 | Added registry user under default_ranger_audit_users | |
ODP-4149 | Set default log level for Infra-Solr to INFO | |
ODP-4087 | Removed Impala Ranger dependency in Hive client setup | |
ODP-4088 | ODP-3277 | Replaced root commands in Hive with sudo-compatible alternatives |
ODP-4088 | ODP-3925 | Changed Kafka controller log level to INFO in 3.0 stack |
ODP-4088 | ODP-3812 | Tuned Kafka2 default configurations for 3.0 stack |
Hadoop
JIRA ID | Apache ID | Description |
|---|---|---|
[Automated] | — | Downgraded HBase from 2.6.2 to 2.5.10 |
HADOOP-18068— | Upgraded AWS SDK to 1.12.132 | |
HADOOP-18101 | Upgraded aliyun-sdk-oss to 3.13.2 and jdom2 to 2.0.6.1 | |
HADOOP-18333 | Upgraded jetty version to 9.4.48.v20220622 | |
ODP-3861 | MAPREDUCE-7201 | Made Job History File Permissions configurable (apache#4507) |
ODP-4994 | — | Aligned projects to internal ODP versions |
ODP-5162 | — | Added CVE fixed versions info in License file |
OSV-5505 | — | Upgraded AWS SDK to 1.12.791 due to CVE |
OSV-5512 | — | Upgraded json-smart to 2.6.0 due to CVE |
OSV-5523 | HADOOP-18333 | Upgraded jetty version to 9.4.57 (#4553) due to CVE |
OSV-5576 | — | Upgraded avro to 1.11.4 due to CVE |
OSV-5583 | — | Upgraded com.fasterxml.jackson.core:jackson-core to 2.16.1 due to CVE |
OSV-5583 | — | Upgraded nimbus-jose-jwt dependencies to 9.37.2 due to CVE |
OSV-5583 | — | CVE-2023-34610: Upgraded de.ruedigermoeller:fst to 2.57 |
OSV-5584 | — | Upgraded netty dependencies to 4.1.127 due to CVE |
HBase
JIRA ID | Apache ID | Description |
|---|---|---|
ODP-2761 | — | Refactored Python script shebangs to use ambari-python-wrap |
Hive
JIRA ID | Apache ID | Description |
|---|---|---|
[Automated] | — | Downgraded HBase from 2.6.2 to 2.5.10 (#103) |
HIVE-27984 | Added support for backward compatibility of HMS Thrift struct for column stats | |
HIVE-28071 | — | Synced Jetty version across modules |
HIVE-28211 | — | Restored hive-exec-core JAR |
ODP-4423 | HIVE-28896 | Upgraded kudu to 1.17.0 |
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-4383 | — | Upgraded PostgreSQL to 42.5.5 to fix CVE-2024-1597 |
OSV-4403 | — | Upgraded libthrift to 0.16.0 to fix CVE-2025-24813 |
OSV-4450 | — | Upgraded parquet to 1.13.1 to fix CVE-2020-10650 |
OSV-4507 | — | Upgraded json-path to 2.9.0 to fix CVE-2023-1370 |
OSV-4516 | — | Upgraded netty to 4.1.127.Final to fix CVE-2025-55163 |
OSV-4520 | — | Upgraded ivy to 2.5.2 to fix CVE-2022-46751 |
OSV-4587 / OSV-4596 | — | Upgraded avatica to 1.23.0 to fix CVE-2020-11620 |
OSV-4591 | — | Upgraded accumulo to 1.10.4 to fix CVE-2025-27553 |
OSV-4592 | — | Upgraded jetty to 9.4.57.v20241219 to fix CVE-2024-13009 |
OSV-4596 | — | Upgraded jackson to 2.14.1 to fix CVE-2022-42003 / 42004 |
OSV-5267 | — | Upgraded Atlas to 2.4.0 due to CVE |
OSV-5827 | — | Upgraded Avro to 1.11.4 due to CVE |
OSV-6571 | — | Upgraded nimbus-jose-jwt to 9.37.2 and jackson to 2.16.1 due to CVE |
Kafka
JIRA ID | Apache ID | Description |
|---|---|---|
ODP-2509 | KAFKA-15498, KAFKA-16825, KAFKA-15208 | Upgraded Jackson versions to fix multiple CVEs |
ODP-4288 | KAFKA-14376 | Added ConfigProvider to support environment variables (KIP-887) |
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-4905 | — | Upgraded jetty to 9.4.57.v20241219 to fix CVE-2024-9823 |
OSV-6917 | — | Upgraded netty to 4.1.127.Final to fix CVE-2025-24970 |
OSV-6939 | — | Upgraded mongo-kafka to 1.13.0 to fix CVE-2024-47561 |
OSV-6942 | — | Upgraded pubsub-group-kafka-connector to 1.3.2 to fix CVE-2023-2976 |
Kafka 3
JIRA ID | Apache ID | Description |
|---|---|---|
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-5706 | — | Upgraded netty to 4.1.127.Final to fix CVEs |
OSV-7524 / OSV-5705 | — | Upgraded mongo-kafka to 2.0.0 to fix CVEs (jackson, avro) |
Knox
JIRA ID | Apache ID | Description |
|---|---|---|
OSV-4597 | Upgraded net.minidev_json-smart to 2.4.9 to resolve CVE | |
OSV-4601 | Upgraded spring-web to 5.3.34 to resolve CVE | |
OSV-4607 | Upgraded org.postgresql_postgresql to 42.4.4 to resolve CVE | |
OSV-4609 | Upgraded org.apache.shiro_shiro-core to 1.12.0 to resolve CVE | |
OSV-4614 | Upgraded org.eclipse.jetty_jetty-server to 9.4.57.v20241219 to resolve CVE | |
OSV-4617 | Excluded snakeyaml to mitigate CVE | |
OSV-4618 | Upgraded spring-core to 5.3.26 to resolve CVE | |
OSV-4624 | Upgraded com.nimbusds_nimbus-jose-jwt to 9.37.3 to resolve CVE | |
ODP-4621 | Upgraded org.apache.mina_mina-core to 2.0.27 to resolve CVE | |
ODP-4672 | Upgraded com.fasterxml.jackson.core_jackson-databind to 2.16.1 to resolve CVE | |
KNOX-2881 | Updated KnoxCLI to handle aliases when testing LDAP (system) authentication | |
KNOX-2895 | Updated KnoxShell to support a dynamic truststore type when connecting to Knox | |
KNOX-3003 | Enhanced the Knox Home page to group services with multiple service URLs | |
KNOX-2896 | Enhanced the Knox Home page with a selectable API services view | |
ODP-4043 | Added support for Apache Pinot | |
ODP-3885 | Included Ambari support for Service Discovery | |
ODP-2718 / ODP-2773 | Refactored Python script shebangs to use ambari-python-wrap | |
ODP-4994 | Aligned projects to internal ODP versions |
Livy
JIRA ID | Apache ID | Description |
|---|---|---|
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-4968 | — | Upgraded netty to 4.1.127.Final to fix CVE-2025-55163 |
Oozie
JIRA ID | Apache ID | Description |
|---|---|---|
[Automated] | — | Downgraded HBase from 2.6.2 to 2.5.10 |
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-5247 | — | Excluded accumulo from sqoop due to CVE |
OSV-5376 | — | Upgraded pig to 0.18.0 due to CVE |
OSV-7083 | — | Excluded pig & hive’s mina-core due to CVE-2024-52046 |
OSV-7086 | — | Upgraded commons-vfs2 to 2.10 due to CVE |
OSV-7092 / OSV-7047 | — | Excluded batik-bridge & transcoder due to CVE |
OSV-7094 | — | Upgraded snappy-java to 1.1.10.4 due to CVE |
OSV-7164 | — | Excluded batik-svgrasterizer due to CVE |
OSV-7173 | — | Upgraded jackson to 2.16.1 due to CVE |
OSV-7184 | — | Upgraded libthrift to 0.9.3-1 due to CVE |
OSV-7242 | — | Upgraded jetty to 9.4.57 due to CVE |
OSV-7243 | — | Upgraded guava to 32.0.1-jre due to CVE |
OSV-7289 | — | Upgraded avro to 1.11.4 due to CVE |
OSV-7292 | — | Upgraded gson to 2.9.0 due to CVE |
OSV-8392 | — | Excluded snakeyaml from sqoop due to CVE |
OSV-8426 | — | Excluded calcite-core from sqoop due to CVE-2022-36364 |
Ozone
JIRA ID | Apache ID | Description |
|---|---|---|
ODP-3773 | HADOOP-18666 | Updated authFilterConfigurationPrefix method to setAuthFilterConfigurationPrefix |
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-5387 | HDDS-12070 | Upgraded Ratis to 3.2.0 due to CVE-2025-24970 |
OSV-5727 / OSV-5831 | — | Upgraded netty to 4.1.127.Final due to CVE |
OSV-7295 | — | Upgraded jetty-server to 9.4.58.v20250814 |
OSV-7296 | HDDS-10876 | Upgraded jackson to 2.16.2 to fix CVE-2025-52999 |
Registry
JIRA ID | Apache ID | Description |
|---|---|---|
Merge PR #17 | — | Merged pull request from acceldata-io/OSV-7676 |
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-5583 | — | Upgraded jackson to 2.16.1 due to CVE |
OSV-7603 | — | Upgraded json-smart to 2.4.9 due to CVE |
OSV-7607 | — | Upgraded logback to 1.2.13 due to CVE |
OSV-7611 | — | Upgraded json to 1.14.4 due to CVE |
OSV-7674 | — | Upgraded jose4j to 0.9.3 due to CVE |
OSV-7681 | — | Upgraded postgres to 42.4.4 and avro to 1.11.4 due to CVEs |
Spark 3
JIRA ID | Apache ID | Description |
|---|---|---|
— | [SPARK-47018] BUILD/SQL | Bumped built-in Hive to 2.3.10 |
— | [SPARK-47738] | Upgraded Kafka to 3.7.0 |
— | [SPARK-51950] | Upgraded Parquet to 1.15.2 |
ODP-1486 / ODP-1303 | SPARK-45732 | Upgraded commons-text to 1.11.0 |
ODP-2583 | — | Upgraded Curator to 5.2.0 |
ODP-2841 | — | Upgraded netty to 4.1.108.Final for CVEs |
ODP-2842 | — | Upgraded commons-compress to 1.26 to fix CVEs |
ODP-2851 | — | Upgraded commons-io to 2.18.0 |
ODP-2866 | — | Upgraded gson and velocity versions |
ODP-3256 | — | Upgraded protobuf-java and gcs-connector to latest builds |
ODP-3257 | — | Upgraded guava to latest releases |
ODP-3361 | — | Upgraded iceberg, netty, and dbcp versions to fix multiple CVEs |
ODP-3411 | — | Upgraded commons-io and gcs-aws-java-sdk-bundle |
ODP-3772 | — | Upgraded datanucleus-core and rdbms |
ODP-3792 | — | Upgraded jackson-databind to 2.17.2 |
ODP-4083 | — | Replaced package with install argument in Spark project |
ODP-4386 | SPARK-45502 | Upgraded Kafka to 3.6.1 |
ODP-4422 | — | Added DeltaLake profile and updated Open Table Format versions |
ODP-4444 | — | Upgraded jetty-server to 9.4.57.v20241219 |
ODP-4446 | — | Upgraded derby to 10.14.3 to fix CVE-2022-46337 |
ODP-4994 | — | Aligned projects to internal ODP versions |
Sqoop
JIRA ID | Apache ID | Description |
|---|---|---|
[Automated] | — | Downgraded HBase from 2.6.2 to 2.5.10 |
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-5254 | — | Upgraded guava to 32.0.1-jre due to CVE |
OSV-5464 | — | Upgraded avro to 1.11.4 due to CVE |
OSV-5472 | — | Upgraded parquet-avro to 1.15.2 due to CVE |
OSV-7184 | — | Upgraded accumulo to 1.10.4 due to CVE |
OSV-7287 | — | Upgraded calcite to 1.25.0.0 to fix CVE-2020-10650 |
OSV-8281 | — | Upgraded jetty to 9.4.57 due to CVE |
Tez
JIRA ID | Apache ID | Description |
|---|---|---|
ODP-4994 | — | Aligned projects to internal ODP versions |
OSV-4306 | — | Upgraded jackson to 2.16.1 due to CVE |
OSV-4322 | — | Upgraded netty to 4.1.127.Final due to CVE |
OSV-5472 | — | Upgraded async-http-client to 2.12.4 due to CVE |
Trino
JIRA ID | Apache ID | Description |
|---|---|---|
[Automated] | — | Downgraded HBase to 2.5.10 |
ODP-4994 | — | Aligned projects to internal ODP versions |
ODP-4994 | — | Fixed hadoop-apache version name |
Zookeeper
JIRA ID | Apache ID | Description |
|---|---|---|
OSV-6376 | — | Upgraded netty to 4.1.127.Final due to CVE |
OSV-6380 | — | Upgraded jackson to 2.16.1 due to CVE |
OSV-6385 | — | Upgraded jetty to 9.4.49.v20220914 |
— | ZOOKEEPER-4627 | Upgraded jetty library |
— | ZOOKEEPER-4700 | Updated Jetty to fix CVE-2023-26048 and CVE-2023-26049 |
— | ZOOKEEPER-4754 | Updated Jetty to fix CVE-2023-36479, CVE-2023-40167, CVE-2023-41900 |
— | ZOOKEEPER-4778 | Updated Netty, Jetty, and Logback to fix multiple CVEs |
— | ZOOKEEPER-4876 | Fixed CVE-2024-6763 in jetty-http-9.4.53.v20231009.jar |
— | ZOOKEEPER-4900 | Upgraded jetty to include fix for CVE-2024-6763 |
Ambari-Mpack
Hue Mpack (4.11.0)
JIRA ID | Description |
|---|---|
ODP-3711 | Added random string generation for secret_key |
ODP-2776 | Refactored Python script shebangs to use ambari-python-wrap |
ODP-4449 | Enabled LDAP configuration through Ambari UI |
Impala Mpack (4.4.0)
JIRA ID | Description |
|---|---|
ODP-4087 | Integrated Ranger plugin via Impala component setup |
JupyterHub Mpack (5.2.1)
JIRA ID | Description |
|---|---|
ODP-3853 | Added compatibility with stack 3.3.6 |
ODP-5247 | Added Python2 support, service user, and other improvements |
ODP-4896 | Added install/uninstall commands in README |
Kafka Mpack (3.7.1)
JIRA ID | Description |
|---|---|
ODP-3853 | Added compatibility with stack 3.3.6 |
ODP-5247 | Added Python2 support, service user, and other improvements |
ODP-4896 | Added install/uninstall commands in README |
NiFi / NiFi-Registry Mpack (1.27.0)
JIRA ID | Description |
|---|---|
ODP-2776 | Refactored Python shebangs to use ambari-python-wrap |
Ozone Mpack (1.4.1)
JIRA ID | Description |
|---|---|
ODP-4197 | Fixed audit filespool directory to use the user-defined log dir |
ODP-4004 | Added HDFS core-site and hdfs-site for Ozone Ranger audits |
ODP-3831 | Upgraded Ozone version to 1.4.1 in mpack |
ODP-2776 | Refactored Python shebangs to use ambari-python-wrap |
ODP-5404 | Loaded environment variables in the classpath when SSL is enabled |
ODP-5219 | Sorted host lists for consistent host assignment |
ODP-4196 | Auto-populated Ozone Ranger audit properties |
Spark3 Mpack (3.5.5)
JIRA ID | Description |
|---|---|
ODP-3967 | Added Spark3 SSL parameters in spark3-defaults.xml |
ODP-5065 | Added mpack for Spark Rapids |
ODP-5428 | Create keytabs for Spark Rapids |
Trino Mpack (472)
JIRA ID | Description |
|---|---|
ODP-5508 | Improved the initial Hive settings |
ODP-4935 ODP-4357 | Fixed the exposed passwords in Trino, support for user-defined Trino users, and automated privilege escalation using polkit |
Backported Ranger Updates from 2.6.0 to ODP v2.5.0.3.2.3.4-2
Apache ID | Description | Version |
|---|---|---|
RANGER-4891 | Replaced PrivilegedAction with PrivilegedExceptionAction in UserGroupInformation.doAs(). | 2.6.0 |
RANGER-4814 | Upgraded Aircompressor library to version 0.27. | 2.6.0 |
RANGER-4912 | Upgraded Spring Framework to version 5.3.39. | 2.6.0 |
RANGER-4809 | Added utility to migrate admin audit logs to x_trx_log_v2 table. | 2.6.0 |
RANGER-4964 | Fixed index issue in x_trx_log table that caused patch failures. | 2.6.0 |
RANGER-5068 | Upgraded RAT Maven plugin to version 0.16.1. | 2.6.0 |
RANGER-5095 | Upgraded Apache Atlas to version 2.4.0 to resolve CVEs. | 2.6.0 |
RANGER-5072 | Upgraded Avro library from 1.11.3 to 1.11.4. | 2.6.0 |
RANGER-5087 | Upgraded Nimbus JOSE + JWT library to version 10.0.1. | 2.6.0 |
RANGER-5091 | Upgraded dnsjava to version 3.6.2 to address CVE-2024-25638. | 2.6.0 |
RANGER-5086 | Upgraded Protobuf to version 3.25.5. | 2.6.0 |
RANGER-5024 | Upgraded Jetty dependency to address CVE-2024-8184. | 2.6.0 |
RANGER-4892 | Upgraded Ranger Tomcat from 8.5.x to 9.x. | 2.6.0 |
RANGER-5001 | Updated policy evaluation to ignore denials for descendant resources. | 2.6.0 |
RANGER-4670 | Made HBase plugin authorization level configurable for table, column family, and column levels. | 2.6.0 |
RANGER-5007 | Exposed service configurations set in Ranger UI for plugin use. | 2.6.0 |
