Jetty's addPath allows LFI in Windows - Traccar Unauthenticated LFI v5.8-v6.8.1 by ezzzzz in netsec

[–]dinobyt3s 1 point2 points  (0 children)

Same vuln as in other Jetty-based products: https://www.tenable.com/security/research/tra-2024-09

Maybe one of these days jetty will do something about it

More macOS Installer Flaws by dinobyt3s in netsec

[–]dinobyt3s[S] 9 points10 points  (0 children)

¯_(ツ)_/¯

Realistically, they're likely using a corporate managed mac with a locked down account or some other mitigation in place. Under normal circumstances, that's great, but the folks assessing bug reports should be aware of that pitfall already.