CVE-2023-49343
Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
- EPSS probability
- 0.03%
- CWE
- CWE-337, CWE-668
- Published
- 2023-12-14
- Last modified
- 2026-03-13
Affected products
- Ubuntu Budgie Budgie Extras
Weakness type
Related vulnerabilities
- CVE-2026-26018 — CoreDNS Loop Detection Denial of Service Vulnerability
- CVE-2026-25235 — PEAR Has a Predictable Verification Hash in Election Account Requests
- CVE-2025-62710 — Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl
- CVE-2025-55069 — AutomationDirect CLICK PLUS Predictable Seed in Pseudo-Random Number Generator
- CVE-2025-20613 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in the firmware for some Intel(R) TDX may...
- CVE-2025-7770 — Predictable Seed in Pseudo-Random Number Generator (PRNG) in Tigo Energy Cloud Connect Advanced
- CVE-2024-7558 — JUJU_CONTEXT_ID is a predictable authentication secret. On a Juju machine (non-Kubernetes) or Juju...
- CVE-2024-22194 — cdo-local-uuid vulnerable to insertion of artifact derived from developer's Present Working Directory into demonstration code