AFAIK, If there are no errata stopping it, then the bootloader can have full rain on the Flash within secure mode. In fact, if it were not able to erase Flash, then the MCU could not be unsecured so it is in the design.
There is an errata stopping it for the old "B" masks:
In normal single chip mode, when security is enabled, it is not possible to launch the Program ($20), Sector-Erase ($40) and Erase- Verify ($05) commands in the Flash. The Mass-Erase ($41) command can be launched.