Vendor
Rebuild versions up to 4.4.7 and 4.5.0-beta5 are vulnerable to an improper authentication flaw in the login component that permits remote attackers to bypass authentication via manipulated requests.