StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
metabase/metabase:v0.46.09ebdc664a6b2
busybox@1.35.0-r29
1.35.0-r30
1
mher/flower:2.051c3c3db5be3
busybox@1.36.1-r2
1.36.1-r6
1
mintproject/data-catalog-db:9be70359feabe03ed55bfdbf92c20a7e43ab928b9bf26fedd848
busybox@1.35.0-r17
1.35.0-r18
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
busybox@1.36.0-r9
1.36.1-r6
1
mintproject/mint-ui-lit:246a8771e8c043f8c1840d3c32262d3d6a9a553208c1a13c3397
busybox@1.35.0-r17
1.35.0-r18
1
mintproject/model-catalog-explorer:0b2f9f0a9124076aeb492add2f123d0757066f6bdeb80c93b4a9
busybox@1.35.0-r17
1.35.0-r18
1
mohameddev006/web-app:v50fbc7360ecf4
busybox@1.35.0-r15
1.35.0-r18
1
mpopoola1/nodejsapp:latest061fc532de7d
busybox@1.35.0-r29
1.35.0-r30
1
muonsoft/openapi-mock:latestc9afe1295484
busybox@1.35.0-r29
1.35.0-r30
1
n8nio/n8n:0.212.0a9195bc499a3
busybox@1.35.0-r17
1.35.0-r18
1
n8nio/n8n:1.33.1dd171d45102a
busybox@1.36.1-r15
1.36.1-r16
1
natsio/nats-box:0.14.31cc420186664
busybox@1.36.1-r15
1.36.1-r16
1
natsio/nats-box:0.13.559cf2e949181
busybox@1.35.0-r29
1.35.0-r30
1
natsio/nats-box:0.13.3c507bd7e3831
busybox@1.35.0-r29
1.35.0-r30
1
natsio/nats-box:0.14.2e808e0644ce1
busybox@1.36.1-r15
1.36.1-r16
1
natsio/nats-kafka:1.4.2bb241956b0dc
busybox@1.36.1-r2
1.36.1-r6
1
natsio/nats-server-config-reloader:0.14.10d50270fa374
busybox@1.36.1-r15
1.36.1-r16
1
natsio/nats-server-config-reloader:0.8.06bdaceb63aa5
busybox@1.35.0-r17
1.35.0-r18
1
natsio/nats-server-config-reloader:0.14.08c28b75bc416
busybox@1.36.1-r0
1.36.1-r6
1
natsio/nats-server-config-reloader:0.11.0c3a755eab2cc
busybox@1.36.1-r0
1.36.1-r6
1
natsio/prometheus-nats-exporter:0.13.02adf791d9f9f
busybox@1.36.1-r2
1.36.1-r6
1
neosu/kubebadges:v0.0.5256530d8e5c6
busybox@1.36.1-r15
1.36.1-r16
1
nginxinc/nginx-unprivileged:1.25-alpine8265b1df5a89
busybox@1.36.1-r15
1.36.1-r16
1
nightscout/cgm-remote-monitor:15.0.2ad29ca7a4de6
busybox@1.35.0-r17
1.35.0-r18
1
nightscout/cgm-remote-monitor:15.0.3f604dc4c03ca
busybox@1.35.0-r17
1.35.0-r18
1
nodered/node-red:3.0.2-18e2632a7a35dd
busybox@1.36.1-r15
1.36.1-r16
1
nottiey/mynodejswebapp:latest9c35a24c9eb3
busybox@1.35.0-r29
1.35.0-r30
1
nsqio/nsq:v1.3.01a369c146af7
busybox@1.36.1-r15
1.36.1-r16
1
okaforuchena/uo-docker:V1.0.0004e81250f48
busybox@1.35.0-r29
1.35.0-r30
1
ooghenekaro/hans-docker:v1.0.0d1f972aa844a
busybox@1.35.0-r29
1.35.0-r30
1
ooghenekaro/nodejswebapp:latestea5b71588a76
busybox@1.35.0-r29
1.35.0-r30
1
ooghenekaro/nodejswebappoct:lateste010f5fecbc7
busybox@1.35.0-r29
1.35.0-r30
1
opencsghq/gitlab-gitaly:v17.5.0bdd2c58b9744
busybox@1:1.35.0-4+b3
no fix listed
1
opencsghq/gitlab-shell:v17.5.0f6d7e7d6be5d
busybox@1:1.35.0-4+b3
no fix listed
1
openhab/openhab-cloud:a8138a329dd2bac8c4b
busybox@1.35.0-r29
1.35.0-r30
1
openkruise/kruise-state-metrics:v0.2.0a8108f771287
busybox@1.35.0-r29
1.35.0-r30
1
openmined/syft-seaweedfs:0.9.53a4144c0bb82
busybox@1.36.1-r15
1.36.1-r16
1
openruntimes/executor:0.11.42228f186dcbb
busybox@1.36.1-r15
1.36.1-r16
1
openspeedtest/latest:v2.0.0d4d62f4b7d85
busybox@1.35.0-r29
1.35.0-r30
1
openverso/ueransim:3.2.6733f1232b7d3
busybox@1.35.0-r17
1.35.0-r18
1
openzipkin/zipkin:2.24197a9692f6a9
busybox@1.36.1-r15
1.36.1-r16
1
opsmx11/issuegen:v2.1.05c50ca123d88
busybox@1:1.21.0-1ubuntu1
no fix listed
1
oranhack7/solidproject:77c6453942223f
busybox@1.36.1-r15
1.36.1-r16
1
oryd/kratos:v1.1.08f15006a080d
busybox@1.36.1-r5
1.36.1-r6
1
oryd/kratos-selfservice-ui-node:v26.2.046a7bac1ad0c
busybox@1.35.0-r29
1.35.0-r30
1
oryd/kratos-selfservice-ui-node:v0.13.0-20d454c21c11bc
busybox@1.35.0-r29
1.35.0-r30
1
owntracks/recorder:0.9.370105145f719
busybox@1.35.0-r17
1.35.0-r18
1
pgpool/pgpool:latest3782cbf9bb0c
busybox@1.35.0-r29
1.35.0-r30
1
phntom/chartmuseum:v0.16.053883b65d9b7
busybox@1.36.1-r0
1.36.1-r6
1
phntom/chartmuseum:v0.15.29242b4df9e65
busybox@1.35.0-r17
1.35.0-r18
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.