StackRadar

CVE-2023-42364

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
603
of 17,787 indexed, latest versions
Container images
635
deployed by those charts
Fix available
2 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 603 of 17,787 indexed charts deploy, on 635 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r29, 1.36.0-r9, 1.36.1-r0, 1.36.1-r1+7 more1.35.0-r31, 1.36.1-r7, 1.36.1-r19, 1.36.1-r29632
busyboxdeb1:1.35.0-4+b3, 1:1.35.0-4+b41:1.35.0-4+deb12u13
OSV records
ALPINE-CVE-2023-42364DEBIAN-CVE-2023-42364

Charts affected

603 by stars
ChartLatestAffected imagesRadar Score
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42364.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r7

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42364.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r31
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r31

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42364.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r7

Open the chart page →

1,588

Container images carrying it

635 by charts deploying them

A fixed version is listed for 2 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/vshn/stardog-userrole-operator:v0.3.04774237c9e86
busybox@1.35.0-r29
1.35.0-r31
1
ghcr.io/waldo-vision/migrate:v0.3.6ae31923312ed
busybox@1.35.0-r29
1.35.0-r31
1
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
busybox@1.35.0-r29
1.35.0-r31
1
ghcr.io/wasi-master/13ft:0.3.4563ce7794a71
busybox@1.36.1-r15
1.36.1-r19
1
ghcr.io/zalando/postgres-operator:v1.12.2d81cda253f5c
busybox@1.36.1-r28
1.36.1-r29
1
public.ecr.aws/cloudnatix/llmariner/envsubst:1.17.0af66e52f852a
busybox@1.36.1-r15
1.36.1-r19
1
public.ecr.aws/cloudnatix/llmariner/envsubst:1.19.1ffc29318c5e9
busybox@1.36.1-r15
1.36.1-r19
1
public.ecr.aws/docker/library/redis:7.0.13-alpine873c49204b64
busybox@1.36.1-r2
1.36.1-r7
1
quay.io/cilium/tetragon:v1.1.096fac2482898
busybox@1.36.1-r15
1.36.1-r19
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
busybox@1.36.0-r9
1.36.1-r7
1
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
busybox@1.35.0-r29
1.35.0-r31
1
quay.io/fiware/vcverifier:2.0.1cd36290dc849
busybox@1.36.0-r9
1.36.1-r7
1
quay.io/frrouting/frr:9.0.2086acb1278fe
busybox@1.36.1-r5
1.36.1-r7
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
busybox@1.36.1-r0
1.36.1-r7
1
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
busybox@1.35.0-r29
1.35.0-r31
1
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
busybox@1.35.0-r29
1.35.0-r31
1
quay.io/jupyterhub/k8s-network-tools:3.3.7310daf3451e3
busybox@1.36.1-r5
1.36.1-r7
1
quay.io/jupyterhub/k8s-network-tools:3.2.1e532a2dc4761
busybox@1.36.1-r2
1.36.1-r7
1
quay.io/kiwigrid/k8s-sidecar:1.25.2cb4c638ffb1f
busybox@1.36.1-r2
1.36.1-r7
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
busybox@1.35.0-r29
1.35.0-r31
1
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
busybox@1.35.0-r29
1.35.0-r31
1
quay.io/maxiv/storageclass-router:0.4.160725dab588c
busybox@1.36.1-r15
1.36.1-r19
1
quay.io/metallb/controller:v0.14.4bbef1ee3e7d3
busybox@1.36.1-r15
1.36.1-r19
1
quay.io/metallb/speaker:v0.14.437611bde45a2
busybox@1.36.1-r15
1.36.1-r19
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
busybox@1.35.0-r29
1.35.0-r31
1
quay.io/spotahome/redis-operator:latest8c772955184e
busybox@1.36.1-r2
1.36.1-r7
1
quay.io/wi_stefan/dsba-db-migrations:0.0.125b986cd14a08
busybox@1.35.0-r29
1.35.0-r31
1
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
busybox@1.36.1-r5
1.36.1-r7
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
busybox@1.36.1-r5
1.36.1-r7
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
busybox@1.36.1-r2
1.36.1-r7
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
busybox@1.35.0-r29
1.35.0-r31
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
busybox@1.36.1-r15
1.36.1-r19
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
busybox@1.36.0-r9
1.36.1-r7
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
busybox@1.35.0-r29
1.35.0-r31
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
busybox@1.36.1-r15
1.36.1-r19
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.