StackRadar

CVE-2022-28391

High

Advisory

Published 3 Apr 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.035
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
514
of 17,781 indexed, latest versions
Container images
535
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 514 of 17,781 indexed charts deploy, on 535 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.31.1-r16, 1.31.1-r19, 1.31.1-r20, 1.31.1-r21+11 more1.31.1-r22, 1.32.1-r8, 1.33.1-r7, 1.34.1-r5535
OSV records
ALPINE-CVE-2022-28391

Charts affected

514 by stars
ChartLatestAffected imagesRadar Score
frpcwenerme1.0.11 of 1See more

frpc wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
busybox@1.33.1-r3
1.33.1-r7

Open the chart page →

3,359
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
longhornio/longhorn-ui:v1.2.3148598de4b7d
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

15,230
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
busybox@1.33.1-r2
1.33.1-r7

Open the chart page →

2,634
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
busybox@1.32.1-r2
1.32.1-r8

Open the chart page →

2,555
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
busybox@1.32.1-r7
1.32.1-r8
temporalio/server:1.15.1e26758f5a1bf
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

22,665
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
busybox@1.31.1-r19
1.31.1-r22

Open the chart page →

1,843
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

2,616
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
busybox@1.33.1-r6
1.33.1-r7

Open the chart page →

2,534
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
busybox@1.34.1-r4
1.34.1-r5

Open the chart page →

1,752
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

3,023
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
edoburu/pgbouncer:1.12.0abc0a4123a81
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

3,697
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

3,118

Container images carrying it

535 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/node:16.13.0-alpine60ef0bed1dc2
busybox@1.33.1-r6
1.33.1-r7
1
library/postgres:14.1-alpine578ca5c8452c
busybox@1.34.1-r3
1.34.1-r5
1
library/postgres:12.3-alpine7693f2082c68
busybox@1.31.1-r16
1.31.1-r22
1
library/postgres:13.3-alpinee98a69a83639
busybox@1.33.1-r3
1.33.1-r7
1
library/rabbitmq:3.7-management-alpinee97f6bb68aab
busybox@1.31.1-r16
1.31.1-r22
1
library/redis:6.2.4-alpine3.1427cc6e902bde
busybox@1.33.1-r2
1.33.1-r7
1
library/redis:6.0.7-alpine5326e0af4341
busybox@1.31.1-r16
1.31.1-r22
1
library/redis:6.0.9-alpine68d4030e0791
busybox@1.31.1-r19
1.31.1-r22
1
library/sonarqube:9.1.0-datacenter-search7e43ff493a47
busybox@1.33.1-r6
1.33.1-r7
1
library/sonarqube:8.9.2-community88cd63154d4b
busybox@1.31.1-r20
1.31.1-r22
1
library/sonarqube:9.1.0-datacenter-appa9bc5a3a1fc3
busybox@1.33.1-r6
1.33.1-r7
1
library/telegraf:1.19.0-alpine794079a7f241
busybox@1.31.1-r20
1.31.1-r22
1
library/telegraf:1.19-alpineaddb86c0c520
busybox@1.34.1-r4
1.34.1-r5
1
library/traefik:2.5.62f603f8d3abe
busybox@1.33.1-r6
1.33.1-r7
1
library/traefik:2.5.47d0228d19042
busybox@1.33.1-r6
1.33.1-r7
1
librenms/librenms:22.4.14f1f3d667cc7
busybox@1.34.1-r3
1.34.1-r5
1
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
busybox@1.31.1-r19
1.31.1-r22
1
lissy93/dashy:2.0.51991f7be5ed0
busybox@1.34.1-r3
1.34.1-r5
1
litmuschaos/curl:2.6.00f3ea466cb9e
busybox@1.33.1-r2
1.33.1-r7
1
litmuschaos/mysql-client:latest251afd8fc039
busybox@1.31.1-r16
1.31.1-r22
1
loftsh/directclusterendpoint:1.14.0310cc7d690f5
busybox@1.33.1-r2
1.33.1-r7
1
loftsh/virtual-cluster:0.0.28023b13bf5898
busybox@1.32.1-r5
1.32.1-r8
1
longhornio/longhorn-ui:v1.2.3148598de4b7d
busybox@1.32.1-r7
1.32.1-r8
1
longhornio/longhorn-ui:v1.1.165560eabe3ee
busybox@1.32.1-r6
1.32.1-r8
1
lsstsqre/lsp-postgres:latest54283318b16b
busybox@1.31.1-r16
1.31.1-r22
1
maelvls/users-grpc:1.1.1c375ab9b48dd
busybox@1.31.1-r19
1.31.1-r22
1
marcinkujawski/flask-app:2.0.1a455017b9d0e
busybox@1.34.1-r3
1.34.1-r5
1
mathnao/certs:1.1.12d38581b447ad
busybox@1.31.1-r20
1.31.1-r22
1
mattermost/focalboard:0.6.7f2f987dada52
busybox@1.32.1-r6
1.32.1-r8
1
mattermost/mattermost-app-chaosengine:c153e436268954edd67
busybox@1.33.1-r3
1.33.1-r7
1
mesosphere/kubefed:proxyurl4fd8889195fe
busybox@1.32.1-r3
1.32.1-r8
1
metacontrollerio/metacontroller:v2.1.10336993b88e4
busybox@1.34.1-r3
1.34.1-r5
1
metacontrollerio/metacontroller:v2.0.4897c9601d2cc
busybox@1.33.1-r3
1.33.1-r7
1
metalmatze/alertmanager-bot:0.4.3426bc2ca7586
busybox@1.31.1-r19
1.31.1-r22
1
micross/hyperapi:0.2.435f59bc3cd64
busybox@1.34.1-r3
1.34.1-r5
1
milesmcc/shynet:v0.12.0e821e31140f7
busybox@1.33.1-r6
1.33.1-r7
1
miniflux/miniflux:2.0.36e2fb990dae74
busybox@1.34.1-r3
1.34.1-r5
1
minio/minio:RELEASE.2020-12-03T05-49-24Z053f103f4894
busybox@1.31.1-r19
1.31.1-r22
1
minio/minio:RELEASE.2020-09-17T04-49-20Ze2b7b633c250
busybox@1.31.1-r16
1.31.1-r22
1
misskey/misskey:12.110.1e08b7c478093
busybox@1.34.1-r4
1.34.1-r5
1
moby/buildkit:v0.10.0c2aeafaed434
busybox@1.34.1-r3
1.34.1-r5
1
moikot/basic-git-server:0.0.20d941bd30ffa
busybox@1.31.1-r16
1.31.1-r22
1
monitoror/monitoror:44b88edcf51ff
busybox@1.31.1-r16
1.31.1-r22
1
monogramm/docker-dolibarr:13.0-alpine5afd99523984
busybox@1.32.1-r6
1.32.1-r8
1
moul/sshportal:v1.19.3332b603727c3
busybox@1.34.1-r3
1.34.1-r5
1
natsio/nats-operator:0.8.31261dae38389
busybox@1.33.1-r6
1.33.1-r7
1
neilpang/acme.sh:3.0.2595809ad43a2
busybox@1.34.1-r3
1.34.1-r5
1
nerzhul/mc-arm64:2020.10.034215df511f31
busybox@1.31.1-r16
1.31.1-r22
1
netrisai/controller-web-service-migration:4.6.03b2f331ade67
busybox@1.33.1-r6
1.33.1-r7
1
ngoduykhanh/powerdns-admin:0.2.3099371dd9ba6
busybox@1.31.1-r16
1.31.1-r22
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.