Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "ubuntu-advantage-desktop-daemon", "binary_version": "1.10.ubuntu0.20.04.1" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-6388.json"
{ "availability": "No subscription required", "binaries": [ { "binary_name": "ubuntu-advantage-desktop-daemon", "binary_version": "1.10.ubuntu0.22.04.2" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "ubuntu-advantage-desktop-daemon", "binary_version": "1.11ubuntu0.1" } ] }