Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.10.ubuntu0.20.04.1", "binary_name": "ubuntu-advantage-desktop-daemon" }, { "binary_version": "1.10.ubuntu0.20.04.1", "binary_name": "ubuntu-advantage-desktop-daemon-dbgsym" } ] }
{ "availability": "No subscription required", "ubuntu_priority": "medium", "binaries": [ { "binary_version": "1.10.ubuntu0.22.04.2", "binary_name": "ubuntu-advantage-desktop-daemon" }, { "binary_version": "1.10.ubuntu0.22.04.2", "binary_name": "ubuntu-advantage-desktop-daemon-dbgsym" } ] }