Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-60913

Remove network discovery services

    Details

    • Type: Task
    • Status: Resolved (View Workflow)
    • Priority: Minor
    • Resolution: Duplicate
    • Component/s: core
    • Labels:
      None
    • Similar Issues:
    • Released As:
      Jenkins 2.220

      Description

      Dating back many years, Jenkins has supported two network discovery services (UDP multicast/broadcast and DNS multicast). When this was first implemented this may have been a reasonable way to provide useful lookup services. With modern Jenkins capabilities, networks, and security considerations, this is no longer a good mechanism. There are now other ways to accomplish the real needs and concerns with doing it this way.

      With Jenkins Security Advisory 2020-01-29 these services were disabled by default because of SECURITY-1641 / CVE-2020-2100.

      These should just be removed.

        Attachments

          Issue Links

            Activity

            Hide
            jglick Jesse Glick added a comment -
            Show
            jglick Jesse Glick added a comment - See JENKINS-33596 .
            Hide
            oleg_nenashev Oleg Nenashev added a comment -

            It was released in Jenkins 2.220. Jeff Thompson it would be great if the pull request submitter ensures to address comments about duplication. I missed it, because I do not always check Jira before merging

            Show
            oleg_nenashev Oleg Nenashev added a comment - It was released in Jenkins 2.220. Jeff Thompson it would be great if the pull request submitter ensures to address comments about duplication. I missed it, because I do not always check Jira before merging
            Hide
            jthompson Jeff Thompson added a comment -

            Oleg Nenashev, I'm not sure what you're asking for. You wanted a reference to the ticket Jesse mentioned to also be included in the PR on GitHub?

            I noticed that you said you were going to do something like that, so I figured you would take care of what you thought was needed. And it was already mentioned here and at least one other place.

             

            Show
            jthompson Jeff Thompson added a comment - Oleg Nenashev , I'm not sure what you're asking for. You wanted a reference to the ticket Jesse mentioned to also be included in the PR on GitHub? I noticed that you said you were going to do something like that, so I figured you would take care of what you thought was needed. And it was already mentioned here and at least one other place.  

              People

              • Assignee:
                jthompson Jeff Thompson
                Reporter:
                jthompson Jeff Thompson
              • Votes:
                0 Vote for this issue
                Watchers:
                3 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved: