CVE-2024-6388
27.06.2024, 16:15
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_advantage_desktop_pro | 𝑥 < 1.12 |
canonical | ubuntu_advantage_desktop_daemon | 𝑥 < 1.12 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control SphereThe application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
- CWE-319 - Cleartext Transmission of Sensitive InformationThe software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
References