关键漏洞信息 漏洞标题 Improper permission handling in the REST endpoints and release notes display of the FRS plugin 严重性 Moderate CVSS v3 base metrics: 5.3 / 10 影响 Impact: An attacker can access release notes content or information via the FRS REST endpoints it should not have access to. 受影响版本 Tuleap Community Edition (tuleap): < 16.5.99.1742812323 Tuleap Enterprise Edition (tuleap): - < 16.5-6 - < 16.4-10 修复版本 Tuleap Community Edition 16.5.99.1742812323 Tuleap Enterprise Edition 16.5-6 Tuleap Enterprise Edition 16.4-10 CVE ID CVE-2025-30209 弱点 CWE-863 参考链接 request #42251: Release notes display of the FRS plugin does not verify permissions 34af2d5 https://tuleap.net/plugins/git/tuleap/tuleap/stable?a=commit&h=34af2d5d10b0349967129f53427f495815e5bbcc