I'm from the Jenkins project. I wish the authors of this post gave us a heads up beforehand. It put our users at unnecessary risk. At Jenkins project, We've published a mitigation script ( https://jenkins-ci.org/content/mitigating-unauthenticated-re... ) while we work out a better fix for users.
I guess they really wanted those minutes of fame.