The flaw may expose user credentials