Exposure of Sensitive System Information to an Unauthorized Control Sphere
CVE-2024-6388
Summary
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
- LOW
- LOCAL
- NONE
- CHANGED
- REQUIRED
- LOW
- HIGH
- NONE
CWE-497 - Exposure of Sensitive System Information to an Unauthorized Control Sphere
The application does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the application does.
References
Advisory Timeline
- Published