StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/devops-ia/kafka-cruise-control-ui:0.4.096c25035cb02
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/dexidp/dex:v2.35.313964b29d63e
busybox@1.35.0-r17
1.35.0-r18
1
ghcr.io/dexidp/dex:v2.37.0f579d00721b0
busybox@1.36.1-r0
1.36.1-r6
1
ghcr.io/dodevops/azure-advanced-backup:0.4.01041d4449e49
busybox@1.35.0-r15
1.35.0-r18
1
ghcr.io/einstack/glide:0.0.1-alpineab3f7d0a1d50
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/estahn/k8s-image-swapper:1.5.102f5be9cde5f9
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/estaid-app/pgbouncer-docker:1.22.07e5630757299
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/eugenmayer/nist-data-mirror:0.1.1a2162df94729
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/exposr/exposrd:v0.12.0561c8f23bdb6
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/extrality/cert-manager-webhook-namecheap:lateste3552fa0c68a
busybox@1.36.1-r0
1.36.1-r6
1
ghcr.io/fernferret/mediawiki-backup:v0.2.2bbef381294ed
busybox@1.35.0-r17
1.35.0-r18
1
ghcr.io/flatcar/flatcar-linux-update-operator:v0.10.0-rc1f9063e20b1f6
busybox@1.36.1-r0
1.36.1-r6
1
ghcr.io/formancehq/dex:v1.0.4b803fbe1cdb8
busybox@1.35.0-r17
1.35.0-r18
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lcpserver:1.9.0324f9b7b689c
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/fpetr/readium-lcp-server-docker-helm/lsdserver:1.9.0cdba39e3f3d0
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/gabe565/limo:latest6dfdbc9853bb
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/gabe565/matrimony:latestd39a9d7c3e1b
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/gabe565/mnemonic-ninja:latest1fd90a9e4d04
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/gabe565/obico/web:latesta5c1daef46c0
busybox@1.36.1-r5
1.36.1-r6
1
ghcr.io/gotway/gotway:v0.0.137ed73c1979ee
busybox@1.35.0-r13
1.35.0-r18
1
ghcr.io/helm/chartmuseum:v0.16.071d1f1c0179e
busybox@1.36.1-r0
1.36.1-r6
1
ghcr.io/helm/chartmuseum:v0.15.0c298183a5208
busybox@1.35.0-r13
1.35.0-r18
1
ghcr.io/home-assistant/home-assistant:2023.11.3feffc0b8227d
busybox@1.36.1-r2
1.36.1-r6
1
ghcr.io/ideamixes/object-cloner:2.0.031030fd2f192
busybox@1.36.1-r0
1.36.1-r6
1
ghcr.io/jsclayton/prometheus-plex-exporter:latest18ef1b2197ef
busybox@1.35.0-r17
1.35.0-r18
1
ghcr.io/k10app/basicuserservice:latest2ee057ad3bef
busybox@1.35.0-r17
1.35.0-r18
1
ghcr.io/k10app/businit:latest94c9a3e799c2
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/k10app/catalog:latest639c980be0f1
busybox@1.35.0-r17
1.35.0-r18
1
ghcr.io/k10app/order:lateste1017d0dbd78
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/k8s-at-home/pod-gateway:v1.6.1dcb2d814a4f7
busybox@1.35.0-r15
1.35.0-r18
1
ghcr.io/k8up-io/k8up:v2.3.257419b6d3830
busybox@1.35.0-r13
1.35.0-r18
1
ghcr.io/kluster-manager/fluxcd-addon:v0.0.23acba3df8827
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/kubedb/provider-aws:v0.27.049b1c312e342
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/kubedb/provider-azure:v0.27.0aa0c8526ae5e
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/kubedb/provider-gcp:v0.27.0a1d4cf8b8fe1
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/kubeform/provider-aws:v0.0.1e3d1f1302e49
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/kubeform/provider-azure:v0.0.1ac8459f70f85
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/kubeform/provider-gcp:v0.0.1af77073c184f
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/kubeshop/k8s-sidecar:ignore-initial-events7f583a36a764
busybox@1.35.0-r17
1.35.0-r18
1
ghcr.io/kvaps/kubefarm-ltsp:v0.13.424efef013a53
busybox@1:1.30.1-4ubuntu6.4
no fix listed
1
ghcr.io/lablabs/cloudflare_exporter:0.0.1670d74ec46602
busybox@1.36.1-r5
1.36.1-r6
1
ghcr.io/leoquote/tencentcloud-exporter:masterca51b6bb15dd
busybox@1.36.1-r2
1.36.1-r6
1
ghcr.io/leprechaun/lgtv2mqtt:latestac2e11c41ffb
busybox@1.36.1-r2
1.36.1-r6
1
ghcr.io/liubin/toml-cli:v0.0.734a1da9f0f83
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/loafoe/solgate:v0.0.12b3256cbc7b68
busybox@1.36.1-r2
1.36.1-r6
1
ghcr.io/loft-sh/agent:3.2.45c109914ff73
busybox@1.36.1-r2
1.36.1-r6
1
ghcr.io/loft-sh/devpod-pro:0.0.0-ci.4-do-not-use5dfa86b6451f
busybox@1.36.1-r5
1.36.1-r6
1
ghcr.io/loft-sh/loft:0.0.0-ci.14b69bcdaa8492
busybox@1.36.1-r2
1.36.1-r6
1
ghcr.io/loft-sh/vcluster:0.16.484f70425f4dd
busybox@1.36.1-r2
1.36.1-r6
1
ghcr.io/loft-sh/vcluster-control-plane:0.0.0-ci.4-do-not-use45e744fc623f
busybox@1.36.1-r5
1.36.1-r6
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.