Document Release note, vulnerabilty section, exposing only a non https API