HomeCanonicalCVE-2024-6388

CVE-2024-6388

MEDIUM
5.9CVSS
Published: 2024-06-27
Updated: 2025-08-27
AI Analysis

Description

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N
Attack Vector
local
Complexity
low
Privileges
low
User Action
required
Scope
changed
Confidentiality
high
Integrity
none
Availability
none
Weaknesses
CWE-497CWE-319

Metadata

Primary Vendor
CANONICAL
Published
6/27/2024
Last Modified
8/27/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

canonical : ubuntu_advantage_desktop_daemon

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-6388 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com