Tuleap FRS Plugin Improper Permission Handling Vulnerability

Vulnerability

A vulnerability exists in the Tuleap FRS (File Release System) plugin, specifically in the Community and Enterprise Editions, prior to the patched versions. The issue stems from improper permission handling in the REST endpoints, allowing unauthorized access to release notes and related information. This vulnerability can be exploited by accessing specific FRS REST endpoints without the necessary permissions, potentially leading to unauthorized information disclosure.

Impact

Exploitation of this vulnerability allows attackers to access restricted release notes and information through the FRS REST endpoints, bypassing normal permission checks.

Reproduction

To reproduce this vulnerability, send a request to the FRS release notes endpoint for a specific release. The request will succeed even if the user does not have the required permissions to access the release notes, due to the lack of proper permission verification in the endpoint.

Remediation

Users can upgrade to Tuleap Community Edition 16.5.99.1742812323 or Tuleap Enterprise Edition 16.5-6 or 16.4-10 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
2.5
exploitability
9.5
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.