StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
charmcli/soft-serve:v0.4.039523c1a6ba8
busybox@1.35.0-r17
1.35.0-r18
1
chetangautamm/repo:Opensips_Buildb4b94155ff5a
busybox@1:1.21.0-1ubuntu1.4
no fix listed
1
chirpstack/chirpstack-application-server:3fb7667fe037f
busybox@1.35.0-r29
1.35.0-r30
1
chirpstack/chirpstack-network-server:3c0bbbb7a3f1e
busybox@1.35.0-r29
1.35.0-r30
1
chrisfu/docker-wipeout-rewrite:sha-0c4f0614f8b4996a203d
busybox@1.36.1-r2
1.36.1-r6
1
chrislusf/seaweedfs:3.64634b094b2183
busybox@1.36.1-r15
1.36.1-r16
1
chrislusf/seaweedfs:3.56ed80f00fde46
busybox@1.36.1-r2
1.36.1-r6
1
chriswells0/first-mate:1.0.5f3918ec8471c
busybox@1.36.1-r0
1.36.1-r6
1
circleci/container-agent:34d8d0ae5efc3
busybox@1.35.0-r29
1.35.0-r30
1
clickhouse/clickhouse-server:26.701b81d1432c4
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.3810861a2e2d0
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:26.3.1092098d3b31dd
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
clickhouse/clickhouse-server:25.10.2.65e019438e1e05
busybox@1:1.30.1-7ubuntu3.1
no fix listed
1
cloudnativelabs/kube-router:v1.6.00ec7cd73f43f
busybox@1.35.0-r29
1.35.0-r30
1
cnieg/gantt:1.1.2d4b478d76f2a
busybox@1.35.0-r17
1.35.0-r18
1
codecov/self-hosted-api:24.4.10475cb1c3136
busybox@1.36.1-r5
1.36.1-r6
1
codecov/self-hosted-frontend:24.4.1534bc4778073
busybox@1.35.0-r29
1.35.0-r30
1
codecov/self-hosted-gateway:24.4.1de483faad6e5
busybox@1.36.1-r5
1.36.1-r6
1
codecov/self-hosted-worker:24.4.1837f546b479b
busybox@1.36.1-r5
1.36.1-r6
1
coldatom/containers-security-api:latesteae9e82da080
busybox@1.35.0-r29
1.35.0-r30
1
coldatom/containers-security-front:latest7c2fbbb41bcf
busybox@1.35.0-r29
1.35.0-r30
1
commerceexperts/smartquery-service:2.2.09e33ad89baf6
busybox@1.36.1-r15
1.36.1-r16
1
crazymax/rrdcached:1.8.0841b10cdae76
busybox@1.36.0-r9
1.36.1-r6
1
crazymax/rtorrent-rutorrent:3.10-0.9.8-0.13.8fb307f5b87bf
busybox@1.35.0-r29
1.35.0-r30
1
cryptexlabs/authf:0.12.11189c07411d7c
busybox@1.36.1-r15
1.36.1-r16
1
cryptexlabs/swagger-combine-ui:0.2.1ed0bc94fd412
busybox@1.36.1-r15
1.36.1-r16
1
csepulvedab/secret-sync:0.5227a6f2b0ff8
busybox@1.35.0-r17
1.35.0-r18
1
curlimages/curl:8.7.125d29daeb9b1
busybox@1.36.1-r15
1.36.1-r16
1
curlimages/curl:8.1.15af13420d29b
busybox@1.35.0-r29
1.35.0-r30
1
curlimages/curl:8.00.19e886c104cae
busybox@1.35.0-r17
1.35.0-r18
1
curlimages/curl:8.00.0d1658d9c8ef9
busybox@1.35.0-r17
1.35.0-r18
1
czerwonk/ping_exporter:v1.1.394f51e1ef1e2
busybox@1.36.1-r15
1.36.1-r16
1
daledavies/jump:v1.4.10a0c8ad93902
busybox@1.36.1-r15
1.36.1-r16
1
danny1dockerhub/nodejswebapp:lateste434683fcc89
busybox@1.35.0-r29
1.35.0-r30
1
datasaker/dsk-container-agent:latest08b52999f67b
busybox@1.35.0-r17
1.35.0-r18
1
davdiv/musicociel:deva85f99be882c
busybox@1.36.1-r15
1.36.1-r16
1
davidvmar/urjc-davidvmar-rabbitmq:1.0.0e9ce2608f799
busybox@1.35.0-r17
1.35.0-r18
1
ddefrancesco/scoperunner-server:0.2.1daaac6657600
busybox@1.36.1-r15
1.36.1-r16
1
ddosify/selfhosted_frontend:2.7.456dbd7cf0776
busybox@1.36.1-r5
1.36.1-r6
1
ddosify/selfhosted_frontend:4.1.5bf454ab99d89
busybox@1.36.1-r5
1.36.1-r6
1
deepflowce/deepflow-agent:v6.2.6.529332fee7fc2
busybox@1:1.30.1-7ubuntu3
no fix listed
1
deepflowce/deepflow-server:v6.2.6.534fcc526dd59
busybox@1.36.0-r9
1.36.1-r6
1
defactops/defactops-ui:1.0.16825cdf9ba706
busybox@1.36.1-r15
1.36.1-r16
1
deluan/navidrome:0.49.311a24da08977
busybox@1.35.0-r29
1.35.0-r30
1
deluan/navidrome:0.50.02cf4442b0099
busybox@1.36.1-r2
1.36.1-r6
1
devopsfaith/krakend:2.6.34c678c224f67
busybox@1.36.1-r5
1.36.1-r6
1
devopstales/k8s-logrotate:1.093d8a978af05
busybox@1.35.0-r15
1.35.0-r18
1
devopstales/trivy-operator:2.575136aa7a26e
busybox@1.35.0-r29
1.35.0-r30
1
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6
1
dinutac/jinja2docker:2.1.89340dde8a8a4
busybox@1.36.1-r15
1.36.1-r16
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.