Fixed Issues in HBase

Review the list of HBase issues that are resolved in Cloudera Runtime 7.3.2, its service packs, and cumulative hotfixes.

Cloudera Runtime 7.3.2.20000 SP2

CDPD-105335: HBase RPC client connections fail on TLS-enabled clusters
Previously, the HBase RPC client offered only a restricted set of TLS cipher suites when establishing a connection. On clusters with data-in-motion encryption enabled, the client and the HBase RegionServer service could fail to negotiate a common cipher suite, causing TLS handshake errors. As a result, dependent operations failed.

This issue is now fixed. The HBase client now supports a broad range of TLS cipher suites and you can configure and enforce TLS cipher suites on the server side across Master and RegionServer services.

Apache Jira: HBASE-30212

Cloudera Runtime 7.3.2.10000 SP1

CDPD-105033: Missing scanner instance owner check in HBase Thrift and REST services
Previously, HBase Thrift and REST did not verify scanner ownership on fetch and close operations in the scan workflow (open, fetch, close). An authenticated user could read rows from scanners opened by other users or close scanners belonging to other users. For more information, see CVE-2026-49326.

This issue is now fixed. The services verify that the effective user matches the scanner owner before allowing fetch or close operations.

Apache Jira: HBASE-30183

Cloudera Runtime 7.3.2.100 CHF 1

There are no new fixes introduced in this release.

Cloudera Runtime 7.3.2

Cloudera Runtime 7.3.2 resolves HBase issues and incorporates fixes from the service packs and cumulative hotfixes from 7.3.1.100 through 7.3.1.706. For a comprehensive record of all fixes in Cloudera Runtime 7.3.1.x, see Fixed Issues.

There are no fixed issues in this release.