StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/waldo-vision/web:v0.3.65bbc7647df07
busybox@1.35.0-r29
1.35.0-r30
1
ghcr.io/wasi-master/13ft:0.3.4563ce7794a71
busybox@1.36.1-r15
1.36.1-r16
1
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18
1
public.ecr.aws/cloudnatix/llmariner/envsubst:1.17.0af66e52f852a
busybox@1.36.1-r15
1.36.1-r16
1
public.ecr.aws/cloudnatix/llmariner/envsubst:1.19.1ffc29318c5e9
busybox@1.36.1-r15
1.36.1-r16
1
public.ecr.aws/docker/library/caddy:2.6.387cbd356af2e
busybox@1.35.0-r17
1.35.0-r18
1
public.ecr.aws/docker/library/redis:7.0.13-alpine873c49204b64
busybox@1.36.1-r2
1.36.1-r6
1
public.ecr.aws/groundcovercom/loki-proxy:0.1.1783d550ad813
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/bentoml/yatai:1.1.13a5dc9d91de0d
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/cilium/tetragon:v1.1.096fac2482898
busybox@1.36.1-r15
1.36.1-r16
1
quay.io/cilium/tetragon-ci:b6f3056a3f6cf05e366a3e07348f7c0b6265a60f5efd991d218b
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/cloudnativetoolkit/cli-tools:v1.1-v1.8.2d6fd2a9e3273
busybox@1.35.0-r13
1.35.0-r18
1
quay.io/fairwinds/docker-demo:1.4.0d53cb940196c
busybox@1.36.0-r9
1.36.1-r6
1
quay.io/fiware/dsba-pdp:0.3.20cca71497e9e
busybox@1.35.0-r29
1.35.0-r30
1
quay.io/fiware/envoy-configmap-updater:0.4.39eabc3f3e1e2
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/fiware/ishare-auth-provider:0.4.3158108f70f95
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/fiware/vcverifier:2.0.1cd36290dc849
busybox@1.36.0-r9
1.36.1-r6
1
quay.io/frrouting/frr:9.0.2086acb1278fe
busybox@1.36.1-r5
1.36.1-r6
1
quay.io/gkarthics/apid-helper:v0.2.3d7d93debf1f4
busybox@1.36.1-r0
1.36.1-r6
1
quay.io/groundcover/caretta:v0.0.16ed8f5118e3a4
busybox@1.35.0-r29
1.35.0-r30
1
quay.io/groundcover/victoria-metrics:v1.85.380ddeb90d18d
busybox@1.35.0-r29
1.35.0-r30
1
quay.io/jupyterhub/k8s-network-tools:3.3.7310daf3451e3
busybox@1.36.1-r5
1.36.1-r6
1
quay.io/jupyterhub/k8s-network-tools:3.2.1e532a2dc4761
busybox@1.36.1-r2
1.36.1-r6
1
quay.io/k8start/http-headers:1.2.0c7a9987f2ac5
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/kiwigrid/k8s-sidecar:1.21.0710e23b489c5
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/kiwigrid/k8s-sidecar:1.25.2cb4c638ffb1f
busybox@1.36.1-r2
1.36.1-r6
1
quay.io/kubermatic/kubermatic:v2.24.5ebba936046ab
busybox@1.35.0-r29
1.35.0-r30
1
quay.io/kubermatic/machine-controller:v1.57.0476ae867ae56
busybox@1.35.0-r29
1.35.0-r30
1
quay.io/kubermatic/operating-system-manager:v1.3.010081473da43
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/kubernetes-multicluster/kubefed:v0.10.0c4635c95730e
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/maxiv/storageclass-router:0.4.160725dab588c
busybox@1.36.1-r15
1.36.1-r16
1
quay.io/metallb/controller:v0.14.4bbef1ee3e7d3
busybox@1.36.1-r15
1.36.1-r16
1
quay.io/metallb/speaker:v0.14.437611bde45a2
busybox@1.36.1-r15
1.36.1-r16
1
quay.io/netwarps/walletconnect-relay:v2.1.3-rc.15d90b9c193e0
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/opsmxpublic/create-secret:v4.0.4defc3263e0e9
busybox@1.35.0-r29
1.35.0-r30
1
quay.io/opsmxpublic/forwarder-controller:v3.5.7f0c5bebaec96
busybox@1.35.0-r17
1.35.0-r18
1
quay.io/spotahome/redis-operator:latest8c772955184e
busybox@1.36.1-r2
1.36.1-r6
1
quay.io/wi_stefan/dsba-db-migrations:0.0.125b986cd14a08
busybox@1.35.0-r29
1.35.0-r30
1
quay.io/yushiwho/sys-stats:e1f9d778c8d08b95c0b
busybox@1.36.1-r5
1.36.1-r6
1
registry.gitlab.com/bitspur/rock8s/images/kube-commands:3.1880ef8ceffc92
busybox@1.36.1-r5
1.36.1-r6
1
registry.gitlab.com/gitlab-org/build/cng/gitlab-openbao:v2.5.5-gitlab25b7636dfba3f
busybox@1:1.37.0-6+b8
no fix listed
1
registry.gitlab.com/parrotsec/project/parrot-mirror-docker:mainf91b602ca572
busybox@1.36.1-r2
1.36.1-r6
1
registry.gitlab.com/radiology/infrastructure/study-governor:8.0.04e7faf6f8d5f
busybox@1.35.0-r15
1.35.0-r18
1
registry.k8s.io/ingress-nginx/controller:v1.6.415be4666c530
busybox@1.35.0-r29
1.35.0-r30
1
registry.k8s.io/ingress-nginx/controller:v1.10.042b3f0e5d084
busybox@1.36.1-r15
1.36.1-r16
1
registry.k8s.io/ingress-nginx/controller:v1.3.154f7fe2c6c5a
busybox@1.35.0-r17
1.35.0-r18
1
registry.k8s.io/ingress-nginx/controller:v1.8.0744ae2afd433
busybox@1.36.0-r9
1.36.1-r6
1
registry.k8s.io/ingress-nginx/controller:v1.7.07612338342a1
busybox@1.35.0-r29
1.35.0-r30
1
registry.k8s.io/ingress-nginx/controller:v1.3.0d1707ca76d3b
busybox@1.35.0-r14
1.35.0-r18
1
registry.k8s.io/ingress-nginx/controller:v1.10.1e24f39d3eed6
busybox@1.36.1-r15
1.36.1-r16
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.