@adarshv The Patch of Security vulnerabilities depends on few things.
1. The urgency or impact.
2. Fix availability.
3. Subscription and use case based.
If the product is EOL and the vulnerability is fixed in next versions than you will have to upgrade. If there is a Patch (Old) available then you might can apply that.
If you are a customer and you can not upgrade and Patch is only way then you can discuss with Cloudera Support or Sales team to explore the opportunities on that.
Generally the upgrade is most conventional method as this gives some more bug fixes as well as features which will make our experience better.
Cheers!
Was your question answered? Make sure to mark the answer as the accepted solution.
If you find a reply useful, say thanks by clicking on the thumbs up button.