Red Hat Bugzilla – Bug 1258515
jenkins: CSFR vulnerability allowing remote attacker to hijack authentication
Last modified: 2016-11-08 11:22:28 EST
CSFR vulnerability in Jenkins 1.626 was found, allowing remote attackers to hijack the authentication of users for most requests. It can be exploited to change specific settings or execute code.
Report (includes reproducers):
Created jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1258522]
Created python-jenkins tracking bugs for this issue:
Affects: fedora-all [bug 1258523]
You're right! CSFR protection mitigates these attacks and according to upstream https://issues.jenkins-ci.org/browse/SECURITY-199 , this is not a bug. Closing as not a bug.