StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
807
of 17,787 indexed, latest versions
Container images
844
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 807 of 17,787 indexed charts deploy, on 844 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more819
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed25
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

807 by stars
ChartLatestAffected imagesRadar Score
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,611
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,846
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,589

Container images carrying it

844 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
apache/superset:dockerizeafe59523a6c8
busybox@1.36.1-r15
1.36.1-r16
2
chatwoot/chatwoot:v3.1.0d530ab8c1753
busybox@1.36.1-r2
1.36.1-r6
2
clickhouse/clickhouse-server:24.3.3.102-alpinef226fe41f057
busybox@1.36.1-r15
1.36.1-r16
2
clickhouse/clickhouse-server:26.8.2:latestfa394da808cc
busybox@1:1.30.1-7ubuntu3.1
no fix listed
2
cs3org/revad:v1.24.0e80a4d67b352
busybox@1.35.0-r17
1.35.0-r18
2
cs3org/wopiserver:v9.4.202a9e78757b4
busybox@1.35.0-r29
1.35.0-r30
2
curlimages/curl:8.4.04a3396ae573c
busybox@1.36.1-r4
1.36.1-r6
2
curlimages/curl:8.6.0c3b8bee303c6
busybox@1.36.1-r15
1.36.1-r16
2
daniacobext/airports-frontend:latest9eae4d39fc33
busybox@1.35.0-r29
1.35.0-r30
2
dependencytrack/frontend:4.6.124422d762e08
busybox@1.35.0-r17
1.35.0-r18
2
devopsjourney1/mywebapp:latestbd1ec6838570
busybox@1.35.0-r17
1.35.0-r18
2
dtzar/helm-kubectl:3.14.455429449408e
busybox@1.36.1-r15
1.36.1-r16
2
epamedp/krci-portal:0.8.0687acf641097
busybox@1.36.1-r15
1.36.1-r16
2
ethersphere/bee-localchain:latest0558799ca992
busybox@1.36.1-r15
1.36.1-r16
2
filebrowser/filebrowser:v2.23.086e8449ff8ff
busybox@1.35.0-r17
1.35.0-r18
2
grafana/grafana:11.1.0079600c9517b
busybox@1.36.1-r15
1.36.1-r16
2
grafana/grafana:11.1.4886b56d5534e
busybox@1.36.1-r15
1.36.1-r16
2
grafana/loki:3.1.0d947e68a84d9
busybox@1.36.1-r5
1.36.1-r6
2
hashicorp/consul-k8s-control-plane:1.0.2538a3436398d
busybox@1.35.0-r17
1.35.0-r18
2
hashicorp/vault:1.15.26b4e5dadf082
busybox@1.36.1-r2
1.36.1-r6
2
hashicorp/vault-k8s:1.3.15d74a885ae3e
busybox@1.36.1-r2
1.36.1-r6
2
hashicorp/vault-k8s:1.1.0844337076b72
busybox@1.35.0-r17
1.35.0-r18
2
inaccel/driver:latest07271a5c2fe7
busybox@1.36.1-r15
1.36.1-r16
2
inaccel/mkrt:latest187fd448b6f2
busybox@1.35.0-r29
1.35.0-r30
2
inaccel/monitor:2.134bb93de386f
busybox@1.36.1-r15
1.36.1-r16
2
iomesh/localpv-manager:v0.2.0f13deacac3f4
busybox@1.35.0-r17
1.35.0-r18
2
k0sproject/k0s:v1.26.0-k0s.0f04635825d51
busybox@1.35.0-r17
1.35.0-r18
2
kiwigrid/k8s-sidecar:1.24.44138bea678f0
busybox@1.35.0-r17
1.35.0-r18
2
kiwigrid/k8s-sidecar:1.24.35af76eebbba7
busybox@1.35.0-r17
1.35.0-r18
2
krtk6160/galoy-nostrcc82a694f818
busybox@1.35.0-r29
1.35.0-r30
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
busybox@1.35.0-r17
1.35.0-r18
2
lachlanevenson/k8s-kubectl:v1.25.4af5cea3f2e40
busybox@1.35.0-r29
1.35.0-r30
2
library/arangodb:3.11.81e75d74954a4
busybox@1.35.0-r17
1.35.0-r18
2
library/influxdb:2.6.1-alpine44a366dd7724
busybox@1.35.0-r29
1.35.0-r30
2
library/memcached:1.6.23-alpine41d19476c100
busybox@1.36.1-r15
1.36.1-r16
2
library/mongo-express:1.0.2:latest1b23d7976f02
busybox@1.36.1-r5
1.36.1-r6
2
library/nats:2.9.17-alpine1a7b320b2942
busybox@1.36.0-r9
1.36.1-r6
2
library/nats:2.10.7-alpine1bcddab51b80
busybox@1.36.1-r5
1.36.1-r6
2
library/nats:2.10.5-alpine85319e5e541b
busybox@1.36.1-r5
1.36.1-r6
2
library/nextcloud:34.0.3:34.0.3-apacheb97df9e0e1ee
busybox@1:1.37.0-6+b8
no fix listed
2
library/nginx:1.24-alpine77e5d4a6ad90
busybox@1.35.0-r29
1.35.0-r30
2
library/postgres:15.2-alpined9c304353c03
busybox@1.35.0-r29
1.35.0-r30
2
library/postgres:11-alpineea50b9fd617b
busybox@1.36.1-r15
1.36.1-r16
2
library/python:3.7-alpinef3d31c8677d0
busybox@1.36.1-r2
1.36.1-r6
2
library/redis:5.0-alpine1a3c60929533
busybox@1.35.0-r17
1.35.0-r18
2
lncm/bitcoind:v27.0324fec72192e
busybox@1.36.1-r15
1.36.1-r16
2
metabase/metabase:v0.45.21fb334ce4820
busybox@1.35.0-r29
1.35.0-r30
2
mojaloop/role-assignment-service:v2.1.0def4bf273721
busybox@1.36.1-r15
1.36.1-r16
2
natsio/nats-server-config-reloader:0.7.2911ce7ed2f55
busybox@1.35.0-r17
1.35.0-r18
2
natsio/nats-server-config-reloader:0.10.1e414cc7e6f59
busybox@1.35.0-r29
1.35.0-r30
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.