2.4.1
Security release. Fixes two reported advisories plus two further issues of the same classes found while fixing them. Upgrading from 2.4.0 is recommended for every deployment. Read the migration note below first — it affects anyone running behind a reverse proxy. Security fixes Issue Severity Affected Admin-secret brute-force lockout bypass via spoofable client IP (GHSA-93hc-xq3w-xw87) Critical >=…