StackRadar

CVE-2022-28391

High

Advisory

Published 3 Apr 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.035
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
514
of 17,781 indexed, latest versions
Container images
535
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 514 of 17,781 indexed charts deploy, on 535 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.31.1-r16, 1.31.1-r19, 1.31.1-r20, 1.31.1-r21+11 more1.31.1-r22, 1.32.1-r8, 1.33.1-r7, 1.34.1-r5535
OSV records
ALPINE-CVE-2022-28391

Charts affected

514 by stars
ChartLatestAffected imagesRadar Score
frpcwenerme1.0.11 of 1See more

frpc wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
busybox@1.33.1-r3
1.33.1-r7

Open the chart page →

3,359
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
longhornio/longhorn-ui:v1.2.3148598de4b7d
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

15,230
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
busybox@1.33.1-r2
1.33.1-r7

Open the chart page →

2,634
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
busybox@1.32.1-r2
1.32.1-r8

Open the chart page →

2,555
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
busybox@1.32.1-r7
1.32.1-r8
temporalio/server:1.15.1e26758f5a1bf
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

22,665
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
busybox@1.31.1-r19
1.31.1-r22

Open the chart page →

1,843
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

2,616
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
busybox@1.33.1-r6
1.33.1-r7

Open the chart page →

2,534
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
busybox@1.34.1-r4
1.34.1-r5

Open the chart page →

1,752
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

3,023
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
edoburu/pgbouncer:1.12.0abc0a4123a81
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

3,697
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

3,118

Container images carrying it

535 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
thesisrobot/pool:v0.3.3-alpha2d1c388a4bda
busybox@1.31.1-r16
1.31.1-r22
2
tkpd/gripmock:1.10.174441dadcfbd
busybox@1.31.1-r16
1.31.1-r22
2
ghcr.io/dexidp/dex:v2.28.15e88f2205de1
busybox@1.32.1-r3
1.32.1-r8
2
ghcr.io/kvaps/kubernetes-tools:v0.13.4920867eb0bf8
busybox@1.33.1-r6
1.33.1-r7
2
ghcr.io/lissy93/dashy:2.1.1acb40032ad4b
busybox@1.34.1-r3
1.34.1-r5
2
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
busybox@1.31.1-r16
1.31.1-r22
2
absaoss/terraform-controller:v0.0.20ad538a1285a0
busybox@1.31.1-r20
1.31.1-r22
1
acockburn/appdaemon:4.0.83a93281d7e94
busybox@1.32.1-r3
1.32.1-r8
1
adferrand/backuppc:4.4.06fea97b02758
busybox@1.31.1-r16
1.31.1-r22
1
ajanvier/polr:2.3.091ac61b88c85
busybox@1.32.1-r3
1.32.1-r8
1
alex6021710/ai-scale-auth:latest6c7a47e470c3
busybox@1.31.1-r21
1.31.1-r22
1
alex6021710/ai-scale-doer:latest31e533cf7cd3
busybox@1.31.1-r21
1.31.1-r22
1
alex6021710/ai-scale-migrator:latest744b8a924f35
busybox@1.31.1-r21
1.31.1-r22
1
alpine/k8s:1.18.16a41efe02a041
busybox@1.33.1-r2
1.33.1-r7
1
ansiblesemaphore/semaphore:v2.8.5303d1f8684027
busybox@1.32.1-r6
1.32.1-r8
1
apache/apisix:2.10.0-alpineb4eabafa83cc
busybox@1.32.1-r6
1.32.1-r8
1
apache/apisix-dashboard:2.9.0c010ea7d1694
busybox@1.34.1-r3
1.34.1-r5
1
apache/apisix-ingress-controller:1.3.0412f92cde0b3
busybox@1.32.1-r6
1.32.1-r8
1
aquasec/harbor-scanner-trivy:0.20.07ea4aa3d2eb6
busybox@1.32.1-r6
1.32.1-r8
1
balihb/block-pvc-scanner:0.2.45b95e1cf1158
busybox@1.34.1-r3
1.34.1-r5
1
balihb/pod-pvc-mapping:0.2.4ee48e79f5d76
busybox@1.34.1-r3
1.34.1-r5
1
bbvalabs/sensitive-data:1.0.13ea299ae63c0
busybox@1.32.1-r6
1.32.1-r8
1
billimek/prometheus-uptimerobot-exporter:0.0.1f14ccd7aad0e
busybox@1.31.1-r16
1.31.1-r22
1
blockstack/envsubst:latestd64d7430289a
busybox@1.32.1-r6
1.32.1-r8
1
brodul/response-hostname:0.1.0ad1c00a491ad
busybox@1.31.1-r19
1.31.1-r22
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
busybox@1.32.1-r6
1.32.1-r8
1
cbeneke/hcloud-fip-controller:v0.4.1dc658078d7ba
busybox@1.31.1-r16
1.31.1-r22
1
chaosnative/cle-frontend:2.7.007b82a82a702
busybox@1.34.1-r4
1.34.1-r5
1
chaostoolkit/back:latest734f3af86125
busybox@1.31.1-r19
1.31.1-r22
1
chaostoolkit/front:latest7f4a7eb9f7df
busybox@1.31.1-r19
1.31.1-r22
1
chaostoolkit/middle:latestb95ba4961cfc
busybox@1.31.1-r19
1.31.1-r22
1
chirpstack/chirpstack-application-server:3.17.6e0b23dfd24d6
busybox@1.34.1-r3
1.34.1-r5
1
chirpstack/chirpstack-gateway-bridge:3.13.2ce3f2cdca8a9
busybox@1.34.1-r3
1.34.1-r5
1
chirpstack/chirpstack-network-server:3.16.1c98d7fe06bce
busybox@1.34.1-r3
1.34.1-r5
1
clastix/kubectl:v1.2187fabaccb3a6
busybox@1.34.1-r3
1.34.1-r5
1
clastix/kubectl:v1.22d0376d87ac6b
busybox@1.34.1-r3
1.34.1-r5
1
cloudecho/hello:0.1.0f76ede067ab9
busybox@1.33.1-r3
1.33.1-r7
1
cloudentity/openbanking-quickstart-bank:1.11.19402ec4b5016
busybox@1.33.1-r2
1.33.1-r7
1
cloudentity/openbanking-quickstart-configuration:1.11.18a1890eb8265
busybox@1.33.1-r2
1.33.1-r7
1
cloudentity/openbanking-quickstart-consent-admin-portal:1.11.1ee83cdd45b7b
busybox@1.33.1-r2
1.33.1-r7
1
cloudentity/openbanking-quickstart-consent-page:1.11.15728654cecb7
busybox@1.33.1-r2
1.33.1-r7
1
cloudentity/openbanking-quickstart-consent-self-service-portal:1.11.18ca94ae6acf4
busybox@1.33.1-r2
1.33.1-r7
1
cloudentity/openbanking-quickstart-financroo-tpp:1.11.1c04eb10c77b7
busybox@1.33.1-r2
1.33.1-r7
1
conduction/agendaservice-php:latest9cfeeb6c7c20
busybox@1.31.1-r16
1.31.1-r22
1
conduction/balance-registration-php:devc36094a41369
busybox@1.31.1-r16
1.31.1-r22
1
conduction/betaalservice-php:latestece1ab544c57
busybox@1.31.1-r16
1.31.1-r22
1
conduction/checkin-component-php:dev3423845692c1
busybox@1.31.1-r16
1.31.1-r22
1
conduction/conduction-ui-php:dev2744565516e8
busybox@1.31.1-r16
1.31.1-r22
1
conduction/contactmoment-component-php:deve1d4ad1e22a8
busybox@1.31.1-r16
1.31.1-r22
1
conduction/docparser-php:devb6f95c8ead7d
busybox@1.31.1-r16
1.31.1-r22
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.