CSFR vulnerability in Jenkins 1.626 was found, allowing remote attackers to hijack the authentication of users for most requests. It can be exploited to change specific settings or execute code. Report (includes reproducers): http://seclists.org/bugtraq/2015/Aug/161
Created jenkins tracking bugs for this issue: Affects: fedora-all [bug 1258522]
Created python-jenkins tracking bugs for this issue: Affects: fedora-all [bug 1258523]
You're right! CSFR protection mitigates these attacks and according to upstream https://issues.jenkins-ci.org/browse/SECURITY-199 , this is not a bug. Closing as not a bug.