CVE Database · CVE-2024-6388
CVSS v3.1
5.9
EPSS
0.15%
Published
Jun 27, 2024
Modified
Aug 27, 2025
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:NWeaknesses (CWE)
Affected Products (1)
References (6)