Overview
About vulnerability
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:Details
- Affected product:
- Ubuntu 18.04 ELS , Ubuntu 20.04 ELS
- Affected packages:
- ubuntu-advantage-tools @ 34 (+1 more)