•  
      request #42251 Improper permission handling in the REST endpoints and release notes display of the FRS plugin
    Infos
    #42251
    Thomas Gerbet (tgerbet)
    2025-03-31 10:17
    2025-03-21 11:00
    43927
    Details
    Improper permission handling in the REST endpoints and release notes display of the FRS plugin

    Impact

    An attacker can access release notes content or information via the FRS REST endpoints it should not have access to.

    CVSSv3.1 score: 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)

    Exploitation

    Access to https://tuleap.example.com/frs/release/<release_id>/release-notes, permissions are not verified at all.

    References

    CWE 863
    CVE-2025-30209

    Delivery/File release system
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2025-03-24
    Attachments
    Empty
    References

    Follow-ups

    User avatar
    Thomas Gerbet (tgerbet)2025-03-24 17:37

    CVE-2025-30209 has been assigned to this issue.


    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-03-21 15:43
    • Summary
      -The release notes display of the FRS plugin does not verify permissions 
      +Improper permission handling in the REST endpoints and release notes display of the FRS plugin 
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes
    User avatar
    Thomas Gerbet (tgerbet)2025-03-21 11:04
    • Original Submission
      Something went wrong, the follow up content couldn't be loaded
      Only formatting have been changed, you should switch to markup to see the changes