StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
springhack/frpc_ingress:latest4aceb821da88
busybox@1.35.0-r17
1.35.0-r18
1
srini78/nodejswebappeks:latest5d1cbdc6833a
busybox@1.35.0-r29
1.35.0-r30
1
stubin87/tiny-api:v1.1.02e5c42e92ec8
busybox@1.35.0-r17
1.35.0-r18
1
su541/cert-manager-desec-webhook:latest371ee33f83c1
busybox@1.36.1-r0
1.36.1-r6
1
subsquid/substrate-explorer:firesquid0889a857f192
busybox@1.35.0-r29
1.35.0-r30
1
subsquid/substrate-ingest:firesquidfa549779e9b1
busybox@1.35.0-r29
1.35.0-r30
1
sumuduliya/hello-world:latestb7788a2984a3
busybox@1.36.1-r15
1.36.1-r16
1
supabase/gotrue:v2.91.07174d551d720
busybox@1.35.0-r29
1.35.0-r30
1
supermq/vernemq:latest944a0be3563e
busybox@1.36.1-r15
1.36.1-r16
1
svtechnmaa/svtech_icingadb:v1.1.26d91c2e4e882
busybox@1.36.1-r15
1.36.1-r16
1
svtechnmaa/svtech_snmp_manager:v1.0.18e8abe71a46d
busybox@1.36.1-r15
1.36.1-r16
1
svtechnmaa/svtech_syncthing:v1.0.41a75d88031fe
busybox@1.36.1-r15
1.36.1-r16
1
swaggerapi/swagger-ui:v4.15.511b20aebb92c
busybox@1.35.0-r17
1.35.0-r18
1
swaggerapi/swagger-ui:v5.6.2342808e22de4
busybox@1.36.1-r2
1.36.1-r6
1
swaggerapi/swagger-ui:v4.15.27ff9a86f35ff
busybox@1.35.0-r17
1.35.0-r18
1
sysintelligent/hello-app:2.0.177fb30df847d
busybox@1.35.0-r29
1.35.0-r30
1
tailwarden/komiser:3.1.103f68c8ae7993
busybox@1.35.0-r17
1.35.0-r18
1
tawfiq58/express-server:latestc707555f6853
busybox@1.35.0-r29
1.35.0-r30
1
tdeutsch/podsync:v2.4.2b67186f4c9a5
busybox@1.35.0-r17
1.35.0-r18
1
temporalio/admin-tools:1.22.4258958fe2ff2
busybox@1.36.1-r2
1.36.1-r6
1
temporalio/admin-tools:1.22.0836af062af30
busybox@1.36.1-r0
1.36.1-r6
1
temporalio/admin-tools:1.25.0-tctl-1.18.1-cli-1.0.0cda4901bab53
busybox@1.36.1-r15
1.36.1-r16
1
temporalio/server:1.25.08a5798191dea
busybox@1.36.1-r15
1.36.1-r16
1
temporalio/server:1.22.0ddeebf8bad8f
busybox@1.36.1-r0
1.36.1-r6
1
temporalio/ui:2.30.25c2a3645d09c
busybox@1.36.1-r15
1.36.1-r16
1
temporalio/ui:2.33.05c586a3c8ec5
busybox@1.36.1-r15
1.36.1-r16
1
thecloudspark/app-worker:1.0dbfcfe02bf36
busybox@1.36.1-r15
1.36.1-r16
1
thelande/apcupsd:v1.0.635e3b7caf54d
busybox@1.36.1-r15
1.36.1-r16
1
thesisrobot/lnd:v0.16.4-beta-c287129953689
busybox@1.36.1-r2
1.36.1-r6
1
thirtythreeforty/neolink:latestf564c4f538de
busybox@1.35.0-r29
1.35.0-r30
1
thmmniii/fbs-runner:v1.27.186105349c1a3
busybox@1.36.1-r5
1.36.1-r6
1
tile38/tile38:1.33.4afb7e82f9485
busybox@1.35.0-r17
1.35.0-r18
1
timescale/timescaledb:latest-pg12645fd9e92d76
busybox@1.36.1-r2
1.36.1-r6
1
tiredofit/freescout:php8.2-1.17.725b7cc0658f07
busybox@1.36.1-r15
1.36.1-r16
1
tobirachel/node-project3:v17d9f37154994
busybox@1.35.0-r29
1.35.0-r30
1
tomsajan/netio-exporter:0.0.5fb61907707b8
busybox@1.36.1-r15
1.36.1-r16
1
tranhailong/nfs-server:4.2-2-gcsfuse028662749be2
busybox@1.35.0-r29
1.35.0-r30
1
troglobit/inadyn:v2.10.0f90233d138ae
busybox@1.35.0-r17
1.35.0-r18
1
tundeficky/nodejs-app:v1.0.03cf9a9ce54e8
busybox@1.35.0-r29
1.35.0-r30
1
tusproject/tusd:v1.10.01e457b59fd5b
busybox@1.35.0-r17
1.35.0-r18
1
tusproject/tusd:v1.13.0f8088058b80f
busybox@1.36.1-r2
1.36.1-r6
1
udhos/forward:1.1.312e120d39fdb
busybox@1.36.0-r9
1.36.1-r6
1
udhos/prime:1.0.0e432012dd34a
busybox@1.35.0-r29
1.35.0-r30
1
untergeek/curator:8.0.4de5197f06c3c
busybox@1.35.0-r29
1.35.0-r30
1
vaultwarden/server:1.27.0-alpine7cd450642c54
busybox@1.35.0-r29
1.35.0-r30
1
victoriametrics/victoria-metrics:v1.93.577a9815d0640
busybox@1.36.1-r2
1.36.1-r6
1
victoriametrics/victoria-metrics:v1.95.1f52723a08a44
busybox@1.36.1-r2
1.36.1-r6
1
victoriametrics/vmalert:v1.96.0150cd08fde94
busybox@1.36.1-r15
1.36.1-r16
1
visualregressiontracker/migration:5.0.1f983a1d4306e
busybox@1.36.1-r2
1.36.1-r6
1
visualregressiontracker/ui:5.0.4ca7835844257
busybox@1.35.0-r29
1.35.0-r30
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.