StackRadar

CVE-2022-28391

High

Advisory

Published 3 Apr 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.035
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
514
of 17,787 indexed, latest versions
Container images
535
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 514 of 17,787 indexed charts deploy, on 535 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.31.1-r16, 1.31.1-r19, 1.31.1-r20, 1.31.1-r21+11 more1.31.1-r22, 1.32.1-r8, 1.33.1-r7, 1.34.1-r5535
OSV records
ALPINE-CVE-2022-28391

Charts affected

514 by stars
ChartLatestAffected imagesRadar Score
frpcwenerme1.0.11 of 1See more

frpc wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
busybox@1.33.1-r3
1.33.1-r7

Open the chart page →

3,359
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
longhornio/longhorn-ui:v1.2.3148598de4b7d
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

15,230
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
busybox@1.33.1-r2
1.33.1-r7

Open the chart page →

2,634
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
busybox@1.32.1-r2
1.32.1-r8

Open the chart page →

2,555
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
busybox@1.32.1-r7
1.32.1-r8
temporalio/server:1.15.1e26758f5a1bf
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

22,665
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
busybox@1.31.1-r19
1.31.1-r22

Open the chart page →

1,843
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

2,616
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
busybox@1.33.1-r6
1.33.1-r7

Open the chart page →

2,534
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
busybox@1.34.1-r4
1.34.1-r5

Open the chart page →

1,752
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

3,023
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
edoburu/pgbouncer:1.12.0abc0a4123a81
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

3,697
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

3,118

Container images carrying it

535 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
wener/frpc:v0.37.0cc9fd4da44c0
busybox@1.33.1-r3
1.33.1-r7
1
wener/frps:v0.37.05c92cc9e8597
busybox@1.33.1-r3
1.33.1-r7
1
wener/samba:4.13.39a42bae466d4
busybox@1.32.1-r2
1.32.1-r8
1
ymuski/skooner:latest67819ca511b5
busybox@1.34.1-r4
1.34.1-r5
1
yuzutech/kroki:0.17.0192b7b27c857
busybox@1.34.1-r3
1.34.1-r5
1
yuzutech/kroki-blockdiag:0.16.07c1917c66d96
busybox@1.33.1-r6
1.33.1-r7
1
yuzutech/kroki-bpmn:0.16.0bd629239a64e
busybox@1.33.1-r6
1.33.1-r7
1
yuzutech/kroki-excalidraw:0.16.015c9eef47a62
busybox@1.33.1-r6
1.33.1-r7
1
yuzutech/kroki-mermaid:0.16.07acc8fe7caba
busybox@1.33.1-r6
1.33.1-r7
1
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
busybox@1.34.1-r3
1.34.1-r5
1
gcr.io/cadvisor/cadvisor:v0.40.0135327c978de
busybox@1.31.1-r20
1.31.1-r22
1
gcr.io/google-samples/microservices-demo/cartservice:v0.2.3566733b4d2d5
busybox@1.31.1-r19
1.31.1-r22
1
gcr.io/google-samples/microservices-demo/checkoutservice:v0.2.30fad1066de77
busybox@1.32.1-r3
1.32.1-r8
1
gcr.io/google-samples/microservices-demo/frontend:v0.2.3ca5c0f0771c8
busybox@1.32.1-r3
1.32.1-r8
1
gcr.io/google-samples/microservices-demo/productcatalogservice:v0.2.35a4a0e54c6d0
busybox@1.32.1-r3
1.32.1-r8
1
gcr.io/google-samples/microservices-demo/shippingservice:v0.2.30cb1707fc503
busybox@1.32.1-r3
1.32.1-r8
1
gcr.io/kubecost1/cost-model:prod-1.81.067f4f162da8d
busybox@1.32.1-r6
1.32.1-r8
1
gcr.io/kubecost1/cost-model:prod-1.82.2989a60847416
busybox@1.33.1-r2
1.33.1-r7
1
gcr.io/kubecost1/frontend:prod-1.81.096dfb19838b8
busybox@1.32.1-r3
1.32.1-r8
1
gcr.io/kubecost1/frontend:prod-1.82.2ba66607c947c
busybox@1.32.1-r6
1.32.1-r8
1
gcr.io/kubecost1/server:prod-1.82.22b1a3d08caac
busybox@1.33.1-r2
1.33.1-r7
1
gcr.io/kubecost1/server:prod-1.81.0a348db3e4d74
busybox@1.32.1-r6
1.32.1-r8
1
ghcr.io/0xerr0r/blocky:v0.18b15824464acb
busybox@1.34.1-r3
1.34.1-r5
1
ghcr.io/alekc/kpubber:v0.0.2a462d5797e14
busybox@1.33.1-r3
1.33.1-r7
1
ghcr.io/alexanderbabel/database-s3-backup:1.3.33191b771a6f2
busybox@1.33.1-r3
1.33.1-r7
1
ghcr.io/andylibrian/terjang:latest20a46b199247
busybox@1.32.1-r6
1.32.1-r8
1
ghcr.io/angelnu/chirpstack-packet-multiplexer:latest0c84c2d71006
busybox@1.32.1-r0
1.32.1-r8
1
ghcr.io/aws-exporters/prometheus-ecr-exporter:0.1.442b0c87470d6
busybox@1.34.1-r3
1.34.1-r5
1
ghcr.io/aws-exporters/prometheus-inspector-exporter:0.0.29c7c11293b3c
busybox@1.34.1-r3
1.34.1-r5
1
ghcr.io/banzaicloud/tcheck:latest0147d87c2019
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/ckotzbauer/chekrf299baf467b5
busybox@1.34.1-r3
1.34.1-r5
1
ghcr.io/conductionnl/adresservice-php:latestc5075f0320cd
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/authorization-component-php:latest94a749392fcf
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/brpservice-php:latestc17f1ba17d36
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/digispoof-interface-php:latest03aba499950f
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/eherkenning-ui-php:latestdeed102b4255
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/grafregistratiecomponent-php:latest35225eaa87ab
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/instemmingservice-php:latest4ffe222b3e3a
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/landelijketabellencatalogus-php:latest26d91dcbba56
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/loggingcomponent-php:latest834b8e1af290
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/logicservice-php:latest72aae2080595
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/memo-component-php:latestef77f4c089a1
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/notification-component-php:latestcd9656e6bc2c
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/ocatiecatalogus-php:latestc22764cbfa97
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/orderregistratiecomponent-php:latestd17257e4fa27
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/procestypecatalogus-php:latest956c4fb64796
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/productenendienstencatalogus-php:latest7242da105081
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/proto-component-commonground-php:latesteb36ead1954e
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/review-component-php:latestafe623824b82
busybox@1.31.1-r16
1.31.1-r22
1
ghcr.io/conductionnl/taalhuizen-service-php:latest04f1b7f0d573
busybox@1.31.1-r16
1.31.1-r22
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.