Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon leaked the Pro token to unprivileged users by passing the token as an argument in plaintext. An attacker could use this issue to gain unauthorized access to an Ubuntu Pro subscription. (CVE-2024-6388)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ubuntu-advantage-desktop-daemon",
"binary_version": "1.10.ubuntu0.20.04.1"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7063-1.json"
{
"ecosystem": "Ubuntu:20.04:LTS",
"cves": [
{
"id": "CVE-2024-6388",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ubuntu-advantage-desktop-daemon",
"binary_version": "1.10.ubuntu0.22.04.2"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7063-1.json"
{
"ecosystem": "Ubuntu:22.04:LTS",
"cves": [
{
"id": "CVE-2024-6388",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "ubuntu-advantage-desktop-daemon",
"binary_version": "1.11ubuntu0.1"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7063-1.json"
{
"ecosystem": "Ubuntu:24.04:LTS",
"cves": [
{
"id": "CVE-2024-6388",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "ubuntu-advantage-desktop-daemon",
"binary_version": "1.10.ubuntu0.16.04.1~esm1"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7063-1.json"
{
"ecosystem": "Ubuntu:Pro:16.04:LTS",
"cves": [
{
"id": "CVE-2024-6388",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
"binaries": [
{
"binary_name": "ubuntu-advantage-desktop-daemon",
"binary_version": "1.10.ubuntu0.18.04.1~esm1"
}
]
}"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7063-1.json"
{
"ecosystem": "Ubuntu:Pro:18.04:LTS",
"cves": [
{
"id": "CVE-2024-6388",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}