An API used to add and remove a favorite was vulnerable to CSRF, allowing attackers to change the victim’s favorites. The API now requires requests to be sent via POST, which is subject to the CSRF protection configurable in Jenkins global security configuration. External References: https://jenkins.io/security/advisory/2017-06-06/ Upstream patch: https://github.com/jenkinsci/favorite-plugin/commit/e51869213ba4f197724f4278a771c635a95e5f47