StackRadar

CVE-2022-28391

High

Advisory

Published 3 Apr 2022In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.035
88th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
514
of 17,781 indexed, latest versions
Container images
535
deployed by those charts
Fix available
1 of 1
affected package

The matching OSV records carry no description.

Carried by container images the latest versions of 514 of 17,781 indexed charts deploy, on 535 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.31.1-r16, 1.31.1-r19, 1.31.1-r20, 1.31.1-r21+11 more1.31.1-r22, 1.32.1-r8, 1.33.1-r7, 1.34.1-r5535
OSV records
ALPINE-CVE-2022-28391

Charts affected

514 by stars
ChartLatestAffected imagesRadar Score
frpcwenerme1.0.11 of 1See more

frpc wenerme 1.0.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/frpc:v0.37.0cc9fd4da44c0
busybox@1.33.1-r3
1.33.1-r7

Open the chart page →

3,359
longhornwenerme1.2.31 of 2See more

longhorn wenerme 1.2.3

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
longhornio/longhorn-ui:v1.2.3148598de4b7d
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

15,230
nats-account-serverwenerme0.8.11 of 1See more

nats-account-server wenerme 0.8.1

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
natsio/nats-account-server:1.0.0a3381560aab6
busybox@1.33.1-r2
1.33.1-r7

Open the chart page →

2,634
sambawenerme1.0.01 of 1See more

samba wenerme 1.0.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
wener/samba:4.13.39a42bae466d4
busybox@1.32.1-r2
1.32.1-r8

Open the chart page →

2,555
temporalwenerme0.15.12 of 13See more

temporal wenerme 0.15.1

2 of the 13 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.15.135034611d981
busybox@1.32.1-r7
1.32.1-r8
temporalio/server:1.15.1e26758f5a1bf
busybox@1.32.1-r7
1.32.1-r8

Open the chart page →

22,665
docker-hub-rate-limit-exporterwiremindVerified publisher0.3.01 of 1See more

docker-hub-rate-limit-exporter wiremind 0.3.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
viadee/docker-hub-rate-limit-exporter:version-1.52e27e3b3ee56
busybox@1.31.1-r19
1.31.1-r22

Open the chart page →

1,843
mrtg-backendwitcom-gmbh0.7.01 of 2See more

mrtg-backend witcom-gmbh 0.7.0

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/oauth2-proxy/oauth2-proxy:v7.2.1febeebebe762
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

2,616
powerdnsadminwitcom-gmbh0.3.41 of 1See more

powerdnsadmin witcom-gmbh 0.3.4

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

2,643
default-backendwyrihaximusnetVerified publisher1.1.01 of 1See more

default-backend wyrihaximusnet 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ghcr.io/wyrihaximusnet/default-backend:randomb24e63efd841
busybox@1.33.1-r6
1.33.1-r7

Open the chart page →

2,534
skoonerxdVerified publisher1.1.01 of 1See more

skooner xd 1.1.0

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
ymuski/skooner:latest67819ca511b5
busybox@1.34.1-r4
1.34.1-r5

Open the chart page →

1,752
rcloneymrs0.1.41 of 2See more

rclone ymrs 0.1.4

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/simplyzee/kube-rclone:v1.52.389a0c23d5ad3
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

1,198
version-checkerymrs0.2.31 of 1See more

version-checker ymrs 0.2.3

1 of the 1 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
quay.io/jetstack/version-checker:v0.2.15f6f8ba0b671
busybox@1.31.1-r16
1.31.1-r22

Open the chart page →

3,023
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
edoburu/pgbouncer:1.12.0abc0a4123a81
busybox@1.32.1-r6
1.32.1-r8

Open the chart page →

3,697
alertmanager-matrix-forwarderzloi-space1.0.11 of 2See more

alertmanager-matrix-forwarder zloi-space 1.0.1

1 of the 2 container images this version deploys carry CVE-2022-28391.

Container imageDigestPackageFixed in
zl0i/alertmanager-matrix-forwarder:v1.0.0e94047931739
busybox@1.34.1-r3
1.34.1-r5

Open the chart page →

3,118

Container images carrying it

535 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
dibi/envsubst:latestfc2d92db8024
busybox@1.31.1-r19
1.31.1-r22
7
quay.io/devtron/authenticator:e414faff-393-13273c8958d9533c7
busybox@1.34.1-r3
1.34.1-r5
6
quay.io/devtron/dex:v2.30.22e4c14d1b444
busybox@1.33.1-r6
1.33.1-r7
6
mailhog/mailhog:v1.0.18d76a3d4ffa3
busybox@1.31.1-r16
1.31.1-r22
5
library/eclipse-mosquitto:1.6.127554e4f05739
busybox@1.31.1-r19
1.31.1-r22
4
grafana/grafana:8.2.500568d89c4f8
busybox@1.33.1-r3
1.33.1-r7
3
kiwigrid/k8s-sidecar:0.1.193170069ff0976
busybox@1.31.1-r16
1.31.1-r22
3
lachlanevenson/k8s-kubectl:v1.23.2e4d83478963b
busybox@1.34.1-r3
1.34.1-r5
3
library/redis:5.0.10-alpine24b1579f6759
busybox@1.32.1-r3
1.32.1-r8
3
nginxinc/nginx-unprivileged:1.19-alpine084242d8028c
busybox@1.32.1-r6
1.32.1-r8
3
p3terx/aria2-pro:202209060423:latest086d1a37c586
busybox@1.31.1-r21
1.31.1-r22
3
xenondb/xenon:1.1.5-alpha0241a1112566
busybox@1.32.1-r6
1.32.1-r8
3
ghcr.io/devplayer0/kubelan:0.2.3b776dae45d08
busybox@1.33.1-r2
1.33.1-r7
3
quay.io/dexidp/dex:v2.25.07bcf286807b8
busybox@1.31.1-r16
1.31.1-r22
3
quay.io/kiwigrid/k8s-sidecar:1.14.235654389f8a9
busybox@1.33.1-r3
1.33.1-r7
3
apteno/alpine-jq:2021-01-1974035b864eed
busybox@1.32.1-r0
1.32.1-r8
2
crate/crate_adapter:latestb8d89fa5d19b
busybox@1.32.1-r6
1.32.1-r8
2
cs3org/revad:v1.19.03b57a34a7dfd
busybox@1.32.1-r7
1.32.1-r8
2
curlimages/curl:7.76.1fa32ef426092
busybox@1.31.1-r20
1.31.1-r22
2
danielfm/aws-limits-exporter:0.6.07152b84e57cb
busybox@1.33.1-r3
1.33.1-r7
2
drone/drone-runner-kube:1.0.0-rc.34359bf2bb3dc
busybox@1.32.1-r7
1.32.1-r8
2
giantswarm/docker-kubectl:1.18.858a9d175cdb7
busybox@1.31.1-r16
1.31.1-r22
2
governify/dashboard:lateste83a17ba5038
busybox@1.33.1-r3
1.33.1-r7
2
grafana/grafana:7.3.5511bc20bfcd1
busybox@1.31.1-r19
1.31.1-r22
2
hashicorp/vault:1.8.34db614d40d0e
busybox@1.33.1-r3
1.33.1-r7
2
hashicorp/vault-k8s:0.13.1bebb03e8e800
busybox@1.33.1-r3
1.33.1-r7
2
jaegertracing/all-in-one:1.3104d224a9999b
busybox@1.33.1-r6
1.33.1-r7
2
jupyterhub/configurable-http-proxy:4.5.08ced0a2f8073
busybox@1.31.1-r20
1.31.1-r22
2
jvstein/bitcoin-prometheus-exporter:v0.6.07645ba790ea8
busybox@1.32.1-r6
1.32.1-r8
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
busybox@1.31.1-r20
1.31.1-r22
2
library/docker:19.03ea1f0761c92b
busybox@1.32.1-r6
1.32.1-r8
2
library/eclipse-mosquitto:1.6.106ba79811d478
busybox@1.31.1-r16
1.31.1-r22
2
library/influxdb:1.8.4-alpinec9eae3860cab
busybox@1.31.1-r20
1.31.1-r22
2
library/nginx:1.19-alpine07ab71a2c8e4
busybox@1.32.1-r6
1.32.1-r8
2
library/postgres:9.6-alpine8342bcb43446
busybox@1.34.1-r3
1.34.1-r5
2
library/postgres:12.4-alpinee27594243877
busybox@1.31.1-r19
1.31.1-r22
2
library/traefik:v2.57d5a6ae66572
busybox@1.33.1-r6
1.33.1-r7
2
listmonk/listmonk:v2.1.0d2eac77ddfad
busybox@1.34.1-r3
1.34.1-r5
2
maxrocketinternet/new-relic-app-exporter:0.185e5f55b6ddc
busybox@1.32.1-r3
1.32.1-r8
2
mesosphere/kommander:6.100.13917e82333a9
busybox@1.33.1-r6
1.33.1-r7
2
minio/mc:RELEASE.2020-11-25T23-04-07Zbf85c57cdfcc
busybox@1.31.1-r16
1.31.1-r22
2
natsio/nats-account-server:1.0.0a3381560aab6
busybox@1.33.1-r2
1.33.1-r7
2
ngoduykhanh/powerdns-admin:v0.2.4ba36ab196d3d
busybox@1.32.1-r6
1.32.1-r8
2
pecan/db:latest9a1cdc3a9ccb
busybox@1.34.1-r3
1.34.1-r5
2
phntom/kochi:1.1.33b82358bd56e
busybox@1.31.1-r19
1.31.1-r22
2
qingcloud/cloud-controller-manager:v1.4.1210f66b5df886
busybox@1.34.1-r3
1.34.1-r5
2
qingcloud/hostnic-plus:v1.0.34cd5366a9f51
busybox@1.32.1-r6
1.32.1-r8
2
sealife/fritzbox-exporter:1.0f5cc2f0f4c9b
busybox@1.31.1-r19
1.31.1-r22
2
statping/statping:v0.90.74e874da513a5c
busybox@1.31.1-r19
1.31.1-r22
2
thesisrobot/loop:v0.11.1-beta89ae07e787ca
busybox@1.31.1-r16
1.31.1-r22
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.