Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may read private information from windows, present false information to users, or deny access to the application.
References
Link | Resource |
---|---|
https://ubuntu.com/security/notices/USN-6556-1 | Vendor Advisory |
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49347 | Third Party Advisory |
https://github.com/UbuntuBudgie/budgie-extras/security/advisories/GHSA-xxfq-fqfp-cpvj | Third Party Advisory |
Configurations
History
20 Dec 2023, 20:41
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CPE | cpe:2.3:a:ubuntubudgie:budgie_extras:*:*:*:*:*:*:*:* | |
CWE | CWE-668 | |
First Time |
Ubuntubudgie budgie Extras
Ubuntubudgie |
|
References | () https://github.com/UbuntuBudgie/budgie-extras/security/advisories/GHSA-xxfq-fqfp-cpvj - Third Party Advisory | |
References | () https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-49347 - Third Party Advisory | |
References | () https://ubuntu.com/security/notices/USN-6556-1 - Vendor Advisory |
14 Dec 2023, 22:44
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-14 22:15
Updated : 2023-12-20 20:41
NVD link : CVE-2023-49347
Mitre link : CVE-2023-49347
JSON object : View
Products Affected
ubuntubudgie
- budgie_extras
CWE
CWE-668
Exposure of Resource to Wrong Sphere