Unauthorized Access in Tuleap Open Source Suite
CVE-2025-30209
5.3MEDIUM
What is CVE-2025-30209?
A vulnerability in the Tuleap Open Source Suite allows attackers to gain unauthorized access to sensitive release notes content via the FRS REST endpoints. This flaw compromises the integrity of information management within the software development lifecycle by exposing data that should remain confidential. It has been addressed in the latest updates, urging users to upgrade to Tuleap Community Edition 16.5.99.1742812323 or Tuleap Enterprise Edition 16.5-6 and 16.4-10.
Affected Version(s)
tuleap < 16.5.99.1742812323