StackRadar

CVE-2022-28391

High

Advisory

Published 3 Apr 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.035
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
514
of 17,781 indexed, latest versions
Container images
535
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 514 of 17,781 indexed charts deploy, on 535 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.31.1-r16, 1.31.1-r19, 1.31.1-r20, 1.31.1-r21+11 more1.31.1-r22, 1.32.1-r8, 1.33.1-r7, 1.34.1-r5535
OSV records
ALPINE-CVE-2022-28391

Charts affected

514 by stars
ChartLatestAffected imagesRadar Score
frpcwenerme1.0.11 of 1See more

frpc wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
busybox@1.33.1-r3
1.33.1-r7

Open the chart page →

3,359
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
longhornio/longhorn-ui:v1.2.3148598de4b7d
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

15,230
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
busybox@1.33.1-r2
1.33.1-r7

Open the chart page →

2,634
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
busybox@1.32.1-r2
1.32.1-r8

Open the chart page →

2,555
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
busybox@1.32.1-r7
1.32.1-r8
temporalio/server:1.15.1e26758f5a1bf
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

22,665
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
busybox@1.31.1-r19
1.31.1-r22

Open the chart page →

1,843
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

2,616
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
busybox@1.33.1-r6
1.33.1-r7

Open the chart page →

2,534
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
busybox@1.34.1-r4
1.34.1-r5

Open the chart page →

1,752
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

3,023
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
edoburu/pgbouncer:1.12.0abc0a4123a81
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

3,697
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

3,118

Container images carrying it

535 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
conduction/kvk-php:dev8f177f9f8a7b
busybox@1.31.1-r16
1.31.1-r22
1
conduction/pan-php:dev24f03c57568f
busybox@1.31.1-r16
1.31.1-r22
1
contribsys/faktory:1.5.15f9a23ee4e86
busybox@1.32.1-r3
1.32.1-r8
1
crazymax/rrdcached:1.7.2-r4042536a06596
busybox@1.33.1-r3
1.33.1-r7
1
curlimages/curl:7.78.0a37d88a5b626
busybox@1.33.1-r2
1.33.1-r7
1
datawire/aes:2.0.3-ea07f8fe4f4f8e
busybox@1.31.1-r20
1.31.1-r22
1
datawire/aes:1.13.62beb65062c8b
busybox@1.31.1-r20
1.31.1-r22
1
datawire/emissary:2.0.2-ea9716efbdd24b
busybox@1.31.1-r20
1.31.1-r22
1
dchesterton/amcrest2mqtt:1.0.9cc70f2238aa9
busybox@1.33.1-r3
1.33.1-r7
1
deluan/navidrome:0.43.04e9ae3bff6aa
busybox@1.32.1-r6
1.32.1-r8
1
denisshav/frontend:latestb97cc69fbac6
busybox@1.32.1-r6
1.32.1-r8
1
devopstales/kube-openid-connector:1.042c40a0e9f1b
busybox@1.34.1-r4
1.34.1-r5
1
deyaeddin/cert-manager-webhook-hetzner:latest797b0d06210a
busybox@1.33.1-r2
1.33.1-r7
1
digitalist/nginx:1.21.6eec27ad73eaa
busybox@1.34.1-r3
1.34.1-r5
1
dniel/forwardauth-spademo:masterd3e38df449a2
busybox@1.33.1-r6
1.33.1-r7
1
dockerid31415926/pod-pvc-mapping:v0.1.3354309669f16
busybox@1.34.1-r3
1.34.1-r5
1
dockerid31415926/pvc-exporter:v0.1.35a1dd17e0e07
busybox@1.34.1-r3
1.34.1-r5
1
dollarshaveclub/furan2:master14a257836529
busybox@1.32.1-r6
1.32.1-r8
1
dollarshaveclub/thermite:0.0.31663cbf25fcfe
busybox@1.33.1-r3
1.33.1-r7
1
duyetdev/applause-btn:latest25e59d223eaa
busybox@1.31.1-r16
1.31.1-r22
1
dysnix/gke-upgrade-notification-handler:latestc166f958f86a
busybox@1.34.1-r3
1.34.1-r5
1
ebrianne/cert-manager-webhook-duckdns:v1.2.39cd17700c9ec
busybox@1.34.1-r3
1.34.1-r5
1
ecadlabs/tezos_exporter:latest4bcbe5d1cdd2
busybox@1.33.1-r2
1.33.1-r7
1
edoburu/pgbouncer:1.12.0abc0a4123a81
busybox@1.32.1-r6
1.32.1-r8
1
eikek0/sharry:1.8.0661ff3ef42cd
busybox@1.32.1-r5
1.32.1-r8
1
elastisys/kube-bench-metrics:0.1.6509b94f1da55
busybox@1.31.1-r19
1.31.1-r22
1
emqx/emqx:4.4.41d36535ba9de
busybox@1.34.1-r4
1.34.1-r5
1
emqx/emqx:4.4.1971db5ed95db3
busybox@1.34.1-r4
1.34.1-r5
1
envoyproxy/envoy-alpine:v1.18.36225750f76e1
busybox@1.31.1-r20
1.31.1-r22
1
envoyproxy/envoy-alpine:v1.16.0bf862e5f5eca
busybox@1.31.1-r16
1.31.1-r22
1
epamedp/codebase-operator:2.12.0-MDTU-DDM-SNAPSHOT.1096028c86f0dd
busybox@1.32.1-r7
1.32.1-r8
1
epamedp/gerrit-operator:2.11.0-MDTU-DDM-SNAPSHOT.2b71fb39e0c9e
busybox@1.32.1-r7
1.32.1-r8
1
epamedp/jenkins-operator:2.11.0-MDTU-DDM-SNAPSHOT.1ff25e9fe4419
busybox@1.32.1-r7
1.32.1-r8
1
epamedp/keycloak-operator:1.11.0-MDTU-DDM-SNAPSHOT.105d352199e12e
busybox@1.32.1-r7
1.32.1-r8
1
epamedp/nexus-operator:2.11.0-MDTU-DDM-SNAPSHOT.1449a53804699
busybox@1.32.1-r7
1.32.1-r8
1
ethereum/client-go:v1.10.15d99fbb9585c7
busybox@1.34.1-r3
1.34.1-r5
1
ethpandaops/blobscan:latest7a9ab6370657
busybox@1.31.1-r21
1.31.1-r22
1
everpcpc/channels:latestb378d137ae8b
busybox@1.33.1-r3
1.33.1-r7
1
factly/dega-studio:0.15.1140fbaa6d555
busybox@1.33.1-r6
1.33.1-r7
1
factly/kavach-web:0.22.30cf361b41798
busybox@1.33.1-r6
1.33.1-r7
1
factly/vidcheck-studio:0.12.024be158ec7d3
busybox@1.32.1-r6
1.32.1-r8
1
felddy/foundryvtt:0.8.36c5d90b90349
busybox@1.32.1-r6
1.32.1-r8
1
filebrowser/filebrowser:v2.18.04fcd47af573c
busybox@1.33.1-r3
1.33.1-r7
1
filebrowser/filebrowser:v2.13.0c5d0a75a0041
busybox@1.32.1-r3
1.32.1-r8
1
fission/fission-bundle:1.14.13fcfd8a0fa5d
busybox@1.32.1-r6
1.32.1-r8
1
fission/pre-upgrade-checks:1.14.1fa0f24cdb9cd
busybox@1.32.1-r6
1.32.1-r8
1
fission/reporter:1.14.104c6e06af175
busybox@1.32.1-r6
1.32.1-r8
1
flant/clickhouse-exporter:0.2.12355a44928d6
busybox@1.31.1-r20
1.31.1-r22
1
fluxcd/helm-controller:v0.9.092b891e495d8
busybox@1.32.1-r3
1.32.1-r8
1
fluxcd/source-controller:v0.10.031a8c79a6803
busybox@1.32.1-r3
1.32.1-r8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.