First published: Thu Jun 27 2024(Updated: )
Last updated 24 July 2024
Credit: security@ubuntu.com security@ubuntu.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ubuntu Advantage Desktop Daemon | <1.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6388 has a medium severity level due to the risk of token leakage.
To fix CVE-2024-6388, update the Ubuntu Advantage Desktop Daemon to version 1.12 or later.
CVE-2024-6388 affects Ubuntu Advantage Desktop Daemon versions prior to 1.12.
CVE-2024-6388 was discovered by Marco Trevisan.
The main issue with CVE-2024-6388 is that it leaks the Pro token to unprivileged users in plaintext.