CVE-2024-6388: Canonical Ubuntu Advantage Desktop Daemon

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.

Affected products

  • Canonical Ubuntu Advantage Desktop Daemon: before 1.12 (fixed in 1.12)

Published 2024-06-27. Last modified 2026-06-17.