VulnerabilityAnalyzed
CVE-2024-6388
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
MEDIUM 5.5EPSS 0.15%
Does this matter?
Lower severity and a low EPSS score (0.15%). Track it; it rarely justifies an emergency change on its own.
Description
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.15% probability · 4th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-497, CWE-319
- Affected
- canonical/ubuntu advantage desktop daemon
- Source
- security@ubuntu.com
References
- https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/2068944Issue Tracking
- https://github.com/canonical/ubuntu-advantage-desktop-daemon/pull/24Issue Tracking, Patch
- https://www.cve.org/CVERecord?id=CVE-2024-6388Third Party Advisory
- https://bugs.launchpad.net/ubuntu/+source/ubuntu-advantage-tools/+bug/2068944Issue Tracking
- https://github.com/canonical/ubuntu-advantage-desktop-daemon/pull/24Issue Tracking, Patch
- https://www.cve.org/CVERecord?id=CVE-2024-6388Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.