StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
phntom/oauth2-proxy:v7.3.48ea656a2a895
busybox@1.35.0-r17
1.35.0-r18
1
phntom/postgresql-backup-s3:1.0.2249b6488f618b
busybox@1.35.0-r29
1.35.0-r30
1
phsmith/rundeck-exporter:2.6.10265a7616ae8
busybox@1.36.0-r9
1.36.1-r6
1
pinclr/v2ray-proxy:latestf37f250b7091
busybox@1.36.0-r9
1.36.1-r6
1
pnnlmiscscripts/k8s-node-image:1.22.17-nginx-362b3ae9b5ec25
busybox@1.36.1-r15
1.36.1-r16
1
pnnlmiscscripts/k8s-node-image:1.24.17-nginx-23952d87cca3d2
busybox@1.36.1-r15
1.36.1-r16
1
pnnlmiscscripts/k8s-node-image:1.23.17-nginx-36a5ee1dea30e4
busybox@1.36.1-r15
1.36.1-r16
1
pnnlmiscscripts/k8s-node-image:1.20.15-nginx-18bbc7a777f9f7
busybox@1.35.0-r13
1.35.0-r18
1
pnnlmiscscripts/k8s-node-image:1.21.14-nginx-36c19a40d7435d
busybox@1.36.1-r15
1.36.1-r16
1
pnnlmiscscripts/k8s-node-image9:1.23.17-nginx-3479ada675515f
busybox@1.35.0-r29
1.35.0-r30
1
pnnlmiscscripts/k8s-node-image9:1.22.17-nginx-34b85e437ae261
busybox@1.35.0-r29
1.35.0-r30
1
pnnlmiscscripts/k8s-node-image9:1.21.14-nginx-33fa8f5906d36a
busybox@1.35.0-r29
1.35.0-r30
1
portainer/portainer-ce:2.18.4-alpine3e61aaee1341
busybox@1.36.1-r0
1.36.1-r6
1
postgis/postgis:15-3.3-alpine4738bee21eb6
busybox@1.36.1-r2
1.36.1-r6
1
postgis/postgis:10-3.2-alpine7e3e68a36d53
busybox@1.35.0-r17
1.35.0-r18
1
prefapp/nginx-proxified:latestf4d026fd9a26
busybox@1.35.0-r17
1.35.0-r18
1
prodrigestivill/postgres-backup-local:12-alpine-8d72d2d6ed2afadc326
busybox@1.35.0-r29
1.35.0-r30
1
prompve/prometheus-pve-exporter:3.4.2fcf041f0c24d
busybox@1.36.1-r15
1.36.1-r16
1
pryorda/vmware_exporter:v0.18.479925e63e59f
busybox@1.35.0-r17
1.35.0-r18
1
pumejlab/nodejs-webapp:latestf563eabcb819
busybox@1.35.0-r29
1.35.0-r30
1
punkerside/noroot:v0.0.7be20c81d6ca1
busybox@1.35.0-r17
1.35.0-r18
1
pvillaverde/radio_dixital:1.5.0326a793e509f
busybox@1.36.1-r15
1.36.1-r16
1
pyaephyohein/mysql2s3bk:alphafdee05f2d441
busybox@1.36.1-r2
1.36.1-r6
1
pysga1996/python-redis-web:latestfdeec30ad482
busybox@1.35.0-r29
1.35.0-r30
1
qbittorrentofficial/qbittorrent-nox:4.6.3-12b86d9c356ae
busybox@1.36.1-r15
1.36.1-r16
1
qumine/ingress-controller:v0.8.5f2c8a2148381
busybox@1.35.0-r17
1.35.0-r18
1
rapidfort/curl:8.7.18483c9f4490f
busybox@1.36.1-r15
1.36.1-r16
1
rclone/rclone:1.63.008e1af3c8814
busybox@1.36.1-r0
1.36.1-r6
1
redis/redisinsight:2.46699d341bd329
busybox@1.36.1-r5
1.36.1-r6
1
reportportal/service-api:5.7.29df41f8fb320
busybox@1.35.0-r14
1.35.0-r18
1
reportportal/service-jobs:5.7.2dc166c58485a
busybox@1.35.0-r14
1.35.0-r18
1
reportportal/service-ui:5.7.20a08784eb901
busybox@1.35.0-r13
1.35.0-r18
1
resouer/redis-slave:v2e2f198b49ba7
busybox@1:1.21.0-1ubuntu1
no fix listed
1
restic/restic:0.15.2579e4e6a4931
busybox@1.35.0-r29
1.35.0-r30
1
rss3/op-batcher:d2c5ced00901227473fc196fda838191f0cb4e02e8adc09d9c07
busybox@1.36.1-r5
1.36.1-r6
1
rss3/op-node:a77d1f52fc3492bf21915bdff8ee8e0b5bd2cb8a45b91380bbe7
busybox@1.36.1-r5
1.36.1-r6
1
rss3/op-proposer:d2c5ced00901227473fc196fda838191f0cb4e0296672897ba9e
busybox@1.36.1-r5
1.36.1-r6
1
rss3/proxyd:6edce9ddfeee0b00a2d98f24c3ce67885653651b865a0a6bdf4c
busybox@1.36.1-r5
1.36.1-r6
1
rss3/proxyd:d2c5ced00901227473fc196fda838191f0cb4e028d9a44c650fa
busybox@1.36.1-r5
1.36.1-r6
1
sealio/hermitcrab:v0.1.4a326a2f03660
busybox@1.36.1-r15
1.36.1-r16
1
sealio/terraform-deployer:v1.5.7-seal.1b0389d9848a5
busybox@1.36.1-r2
1.36.1-r6
1
semaphoreui/semaphore:v2.9.645b50bc11833f
busybox@1.36.1-r5
1.36.1-r6
1
semitechnologies/weaviate:1.19.17a00d226f063
busybox@1.36.0-r9
1.36.1-r6
1
shadowrhyder/gke-volume-autoscaler:3.0.24aae9270356a
busybox@1.36.1-r2
1.36.1-r6
1
shyim/shopware:6.4.6.0a951c0e6b836
busybox@1.35.0-r17
1.35.0-r18
1
sky5367/locust-plugins-grafana:latestd51bf68d4b26
busybox@1.36.1-r15
1.36.1-r16
1
sky5367/locust-plugins-timescale:latestd3150f201471
busybox@1.36.1-r5
1.36.1-r6
1
skylenet/ethereum-testnet-homepage:latest8698903e379f
busybox@1.35.0-r29
1.35.0-r30
1
skylenet/ethstats-server:pow-latestd757cc016198
busybox@1.35.0-r17
1.35.0-r18
1
solidproject/community-server:6.0.2ccc4acb7e9a1
busybox@1.36.1-r2
1.36.1-r6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.