Dear all,
While researching about Traccar I found this topic, are these vulnerabilities true?
https://github.com/traccar/traccar/security/advisories
Two security vulnerabilities have been disclosed in the open-source Traccar GPS tracking system that could be potentially exploited by unauthenticated attackers to achieve remote code execution under certain circumstances.
Both the vulnerabilities are path traversal flaws and could be weaponized if guest registration is enabled, which is the default configuration for Traccar 5, Horizon3.ai researcher Naveen Sunkavally said.
Why dont you use a version above 5.12 ?
It is true if you're using an old version, but all published advisories are already fixed in newer versions.
Great!
Thank you for the update
Dear all,
While researching about Traccar I found this topic, are these vulnerabilities true?
https://github.com/traccar/traccar/security/advisories
Two security vulnerabilities have been disclosed in the open-source Traccar GPS tracking system that could be potentially exploited by unauthenticated attackers to achieve remote code execution under certain circumstances.
Both the vulnerabilities are path traversal flaws and could be weaponized if guest registration is enabled, which is the default configuration for Traccar 5, Horizon3.ai researcher Naveen Sunkavally said.