Impact
The vulnerability is an improper authentication flaw in the Rebuild Login Endpoint. An attacker can manipulate the login process to bypass authentication checks, matching CWE-287. This manipulation allows an attacker to gain unauthorized access to the application and potentially elevate privileges within the system.
Affected Systems
Rebuild versions up to 4.4.7 and the beta release 4.5.0‑beta5 contain the flaw. The affected code lies in the /user/login component of the Login Endpoint. No other versions have been reported as affected.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score is unavailable, but the vulnerability is publicly exploitable and can be triggered remotely. It is not listed in the CISA KEV catalog, and the vendor has not issued a patch, so the risk remains significant until a newer release is deployed.
OpenCVE Enrichment