CVE-2024-6388

MEDIUM

Ubuntu Advantage Desktop Daemon <1.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.

Scores

CVSS v3 5.9
EPSS 0.0002
EPSS Percentile 6.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-319 CWE-497
Status published
Products (1)
canonical/ubuntu_advantage_desktop_daemon < 1.12
Published Jun 27, 2024
Tracked Since Feb 18, 2026