# CVE-2023-49343

## Summary

- **CVE ID:** CVE-2023-49343
- **Severity:** MEDIUM
- **CVSS Score:** 6 (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H)
- **CWE:** CWE-337, CWE-668
- **Published:** Dec 14, 2023
- **Last Modified:** Mar 13, 2026

## Description

Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.

## Affected Products

- Ubuntu Budgie — Budgie Extras (v1.4.0)

## References

- [CNA](https://github.com/UbuntuBudgie/budgie-extras/security/advisories/GHSA-27g2-7x65-3cc5)
- [CNA](https://ubuntu.com/security/notices/USN-6556-1)
- [CNA](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49343)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.03%
- **EPSS Percentile:** 9.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._