CVE-2025-30209: Tuleap has improper permission handling in the REST endpoints and release notes display of the FRS plugin
Tuleap is an Open Source Suite to improve management of software developments and collaboration. An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. This vulnerability is fixed in Tuleap Community Edition 16.5.99.1742812323 and Tuleap Enterprise Edition 16.5-6 and 16.4-10.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30209?
CVE-2025-30209 has a high severity level due to unauthorized access to sensitive information.
How do I fix CVE-2025-30209?
To fix CVE-2025-30209, upgrade to Tuleap Community Edition 16.5.99.174281 or later.
Which versions of Tuleap are affected by CVE-2025-30209?
CVE-2025-30209 affects Tuleap Community Edition versions before 16.5.99.174281 and Tuleap Enterprise Edition versions between 16.4 and 16.5-6.
What type of information can be accessed due to CVE-2025-30209?
CVE-2025-30209 allows attackers to access release notes content or information via the FRS REST endpoints.
Is there a patch available for CVE-2025-30209?
Yes, a patch is available in Tuleap Community Edition version 16.5.99.174281 and later.