Impact
An attacker can access release notes content or information via the FRS REST endpoints it should not have access to.
CVSSv3.1 score: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitation
Access to https://tuleap.example.com/frs/release/<release_id>/release-notes
, permissions are not verified at all.
References
CWE 863
CVE-2025-30209