This is basically GHSA-88j4-pcx8-q4q but instead of changing passwords, when enabling authentication.
See GHSA-g9v2-wqcj-j99g and GHSA-88j4-pcx8-q4q
TBH this is quite a niche edge case, so I don't know if this even warrants a security report.
{ "github_reviewed_at": "2024-04-19T17:26:32Z", "cwe_ids": [ "CWE-384" ], "nvd_published_at": null, "severity": "LOW", "github_reviewed": true }