StackRadar

CVE-2022-28391

High

Advisory

Published 3 Apr 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.035
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
514
of 17,781 indexed, latest versions
Container images
535
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 514 of 17,781 indexed charts deploy, on 535 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.31.1-r16, 1.31.1-r19, 1.31.1-r20, 1.31.1-r21+11 more1.31.1-r22, 1.32.1-r8, 1.33.1-r7, 1.34.1-r5535
OSV records
ALPINE-CVE-2022-28391

Charts affected

514 by stars
ChartLatestAffected imagesRadar Score
frpcwenerme1.0.11 of 1See more

frpc wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
busybox@1.33.1-r3
1.33.1-r7

Open the chart page →

3,359
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
longhornio/longhorn-ui:v1.2.3148598de4b7d
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

15,230
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
busybox@1.33.1-r2
1.33.1-r7

Open the chart page →

2,634
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
busybox@1.32.1-r2
1.32.1-r8

Open the chart page →

2,555
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
busybox@1.32.1-r7
1.32.1-r8
temporalio/server:1.15.1e26758f5a1bf
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

22,665
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
busybox@1.31.1-r19
1.31.1-r22

Open the chart page →

1,843
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

2,616
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
busybox@1.33.1-r6
1.33.1-r7

Open the chart page →

2,534
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
busybox@1.34.1-r4
1.34.1-r5

Open the chart page →

1,752
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

3,023
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
edoburu/pgbouncer:1.12.0abc0a4123a81
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

3,697
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

3,118

Container images carrying it

535 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
interlayhq/interbtc-hydra-processor:master-2c6e16e-1637088364423d567d47aa
busybox@1.33.1-r6
1.33.1-r7
1
itzmanish/ecr-token-renew:latest02154d1c05b5
busybox@1.33.1-r2
1.33.1-r7
1
jaegertracing/all-in-one:1.2942822be7888b
busybox@1.33.1-r6
1.33.1-r7
1
jaegertracing/all-in-one:1.22.0ca6b73330616
busybox@1.31.1-r19
1.31.1-r22
1
jakuboskera/todo:v0.2.3714b1adbbc2d
busybox@1.34.1-r3
1.34.1-r5
1
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
busybox@1.34.1-r3
1.34.1-r5
1
jesec/flood:4.7.03d1d0bec117a
busybox@1.32.1-r6
1.32.1-r8
1
jesec/flood:4.6.060bd59cfb4eb
busybox@1.32.1-r6
1.32.1-r8
1
jesec/rtorrent-flood:latestf0c894ec459e
busybox@1.32.1-r6
1.32.1-r8
1
jfwenisch/alpine-tor:latest9e6c229f953c
busybox@1.32.1-r6
1.32.1-r8
1
jlesage/handbrake:v1.24.25fa191e3c7ee
busybox@1.31.1-r20
1.31.1-r22
1
joeelliott/cert-exporter:v2.7.0b4acd14642d0
busybox@1.31.1-r20
1.31.1-r22
1
johnblack77/clustereye:latest-amd64bb53ceb8442e
busybox@1.32.1-r6
1.32.1-r8
1
julb/alertmanager-gchat-integration:1.0.5837c4038a0dd
busybox@1.32.1-r3
1.32.1-r8
1
julb/http-reqtrace:1.1.00806409af397
busybox@1.31.1-r19
1.31.1-r22
1
julb/kubernetes-configmap-sync:1.1.0d7d8836366ad
busybox@1.31.1-r19
1.31.1-r22
1
jupyterhub/configurable-http-proxy:4.5.1723028bf9b3c
busybox@1.34.1-r3
1.34.1-r5
1
jupyterhub/configurable-http-proxy:4.2.281bd96729c14
busybox@1.31.1-r19
1.31.1-r22
1
jupyterhub/k8s-network-tools:0.11.1e562b1f91469
busybox@1.32.1-r0
1.32.1-r8
1
kanboard/kanboard:v1.2.200b6d33dbbc16
busybox@1.32.1-r6
1.32.1-r8
1
keitaro/ckan-datapusher:0.0.175bf1a45f45c1
busybox@1.31.1-r16
1.31.1-r22
1
keptn/distributor:0.8.36bc3df9e0d6a
busybox@1.32.1-r6
1.32.1-r8
1
keptn/distributor:0.8.472e17527a4f9
busybox@1.32.1-r6
1.32.1-r8
1
keyoxide/keyoxide:stable96f27a71269d
busybox@1.34.1-r3
1.34.1-r5
1
keyporttech/csi-driver-nfs:2.0.05bd7955ea2f1
busybox@1.31.1-r16
1.31.1-r22
1
kfirfer/kibana-index-pattern-updater:1.0.12e88cfcec5c93
busybox@1.31.1-r19
1.31.1-r22
1
kfirfer/percona-xtradb-healthcheck:0.0.1ef7b909a8e6b
busybox@1.31.1-r19
1.31.1-r22
1
kiwigrid/k8s-sidecar:1.1.03e86186656d3
busybox@1.31.1-r16
1.31.1-r22
1
kiwigrid/k8s-sidecar:1.3.065095a82d4a1
busybox@1.31.1-r19
1.31.1-r22
1
kiwigrid/k8s-sidecar:1.12.089739be9ff38
busybox@1.32.1-r6
1.32.1-r8
1
klausmeyer/docker-registry-browser:1.3.5430a440d95af
busybox@1.31.1-r16
1.31.1-r22
1
klausmeyer/docker-registry-browser:1.4.0bdc4c6b8595b
busybox@1.33.1-r3
1.33.1-r7
1
kodgruvan/rsyslog-server:0.1.0ea16adc68593
busybox@1.31.1-r16
1.31.1-r22
1
kubeedge/cloudcore:v1.9.1320b5325a07d
busybox@1.32.1-r7
1.32.1-r8
1
kubeflownotebookswg/centraldashboard:v1.6.137300551dea6
busybox@1.34.1-r3
1.34.1-r5
1
kubemod/kubemod:v0.19.11f8154f7e80c
busybox@1.31.1-r19
1.31.1-r22
1
kubemod/kubemod:v0.13.0cadca39288ad
busybox@1.31.1-r19
1.31.1-r22
1
kvalitetsit/nsp-prometheus-exporter:1.0.190b397ff954ec
busybox@1.31.1-r16
1.31.1-r22
1
kylemanna/openvpn:2.44de5e6690818
busybox@1.31.1-r19
1.31.1-r22
1
lavandadelpatio/frontend:masterccfc0cd77803
busybox@1.33.1-r3
1.33.1-r7
1
layer5/meshery-cpx:stable-latest8c20a8a1d6a4
busybox@1.31.1-r16
1.31.1-r22
1
library/adminer:4.7143ec8cc2f3a
busybox@1.32.1-r2
1.32.1-r8
1
library/alpine:3.15.021a3deaa0d32
busybox@1.34.1-r3
1.34.1-r5
1
library/alpine:3.12.4a295107679b0
busybox@1.31.1-r19
1.31.1-r22
1
library/alpine:3.14.0adab3844f497
busybox@1.33.1-r2
1.33.1-r7
1
library/caddy:2.2.0-alpine7367adca165f
busybox@1.31.1-r16
1.31.1-r22
1
library/caddy:2.4.5874405536b3e
busybox@1.33.1-r3
1.33.1-r7
1
library/caddy:2.4.2-alpinefbc51bcf1ab0
busybox@1.32.1-r6
1.32.1-r8
1
library/haproxy:2.3.9-alpinefd871b2cf0be
busybox@1.32.1-r6
1.32.1-r8
1
library/nginx:1.19.3-alpine5aa44b407756
busybox@1.31.1-r19
1.31.1-r22
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.