Описание
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
Ссылки
- Issue Tracking
- Issue TrackingPatch
- Third Party Advisory
- Issue Tracking
- Issue TrackingPatch
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.12 (исключая)
cpe:2.3:a:canonical:ubuntu_advantage_desktop_daemon:*:*:*:*:*:*:*:*
EPSS
Процентиль: 5%
0.00022
Низкий
5.9 Medium
CVSS3
5.5 Medium
CVSS3
Дефекты
CWE-497
CWE-319
Связанные уязвимости
CVSS3: 5.9
ubuntu
больше 1 года назад
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
CVSS3: 5.9
github
больше 1 года назад
Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
EPSS
Процентиль: 5%
0.00022
Низкий
5.9 Medium
CVSS3
5.5 Medium
CVSS3
Дефекты
CWE-497
CWE-319