Apache Spark 2.x — End of Life

EOL
EOL: May 9, 20215 releases in this series0 CVEs

Apache Spark 2.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatus
2.4LTSOct 29, 2018May 9, 20212.4.8EOL
2.3Feb 22, 2018Aug 25, 20192.3.4EOL
2.2Jun 30, 2017Jan 30, 20192.2.3EOL
2.1Dec 15, 2016Jun 26, 20182.1.3EOL
2.0Jul 19, 2016Dec 15, 20162.0.2EOL

CVEs affecting Apache Spark 2.x (0)

No CVEs tracked for Apache Spark 2.x.

Apache Spark 2.x is EOL — migrate to Apache Spark 3.x

Apache Spark 3.x is the next major release. Plan your upgrade before Apache Spark 2.x stops receiving security patches.

See Apache Spark 3.x

Frequently asked questions

Is Apache Spark 2 end of life?

Yes. All Apache Spark 2.x releases have reached end of life and no longer receive security patches. Migrate to Apache Spark 3.x as soon as possible.

What CVEs affect Apache Spark 2?

No CVEs are currently tracked for Apache Spark 2.x in our database. This may mean no vulnerabilities have been recorded yet, or the data is still syncing.

What is the latest Apache Spark 2 version?

The latest Apache Spark 2.x patch release is 2.4.8, released on May 9, 2021. Always run the latest patch to benefit from all security fixes.

How to migrate from Apache Spark 2 to Apache Spark 3?

To migrate from Apache Spark 2 to Apache Spark 3: (1) review the official Apache Spark 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Apache Spark 2 in production?

No. Apache Spark 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA