StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
dipugodocker/pdf-editor:1.0-backend-rotate316e203b8bf5
busybox@1.35.0-r15
1.35.0-r18
1
dipugodocker/pdf-editor:1.0-backend-merge70b07544a604
busybox@1.35.0-r15
1.35.0-r18
1
distribution/distribution:2.8.3f84b2078238f
busybox@1.36.1-r2
1.36.1-r6
1
djjudas21/autonodelabel:0.0.6f17233350c4f
busybox@1.36.1-r0
1.36.1-r6
1
djjudas21/dbdump:0.0.917fc245e29bd
busybox@1.36.1-r15
1.36.1-r16
1
dnsforge/xteve:latest4d9a685c8c28
busybox@1.35.0-r29
1.35.0-r30
1
dockurr/strfry:1.1.0545555da5dd2
busybox@1.36.1-r2
1.36.1-r6
1
dongjiang1989/cosign-webhook:v1.1.02a3ead6a55dc
busybox@1.36.1-r2
1.36.1-r6
1
dongjiang1989/cpusets-controller:v1.1.1dc5bd483874c
busybox@1.36.1-r0
1.36.1-r6
1
dongjiang1989/cpusets-device-plugin:v1.1.1923085c65123
busybox@1.36.1-r0
1.36.1-r6
1
dongjiang1989/crane-scheduler-controller:mainf0055c05dbee
busybox@1.36.0-r9
1.36.1-r6
1
dongjiang1989/ns-node-affinity:latest451f7823723c
busybox@1.35.0-r29
1.35.0-r30
1
dpage/pgadmin4:8.418cd5711fc9a
busybox@1.36.1-r15
1.36.1-r16
1
dpage/pgadmin4:7.537946e4f3e7b
busybox@1.36.1-r0
1.36.1-r6
1
dragonflyoss/manager:v2.1.49c3ef7f10698d
busybox@1.35.0-r29
1.35.0-r30
1
dragonflyoss/scheduler:v2.1.49523785c77787
busybox@1.35.0-r29
1.35.0-r30
1
dserio83/velero-ui:0.3.1b4e1ec6664d3
busybox@1.36.1-r15
1.36.1-r16
1
dtzar/helm-kubectl:3.11.2a1041bb0f1d1
busybox@1.35.0-r29
1.35.0-r30
1
ealen/echo-server:0.6.0359761caae37
busybox@1.35.0-r13
1.35.0-r18
1
envsubst/envsubst:latest90963c70db69
busybox@1.36.1-r2
1.36.1-r6
1
epamedp/admin-console-operator:2.14.090f9921d8d58
busybox@1.35.0-r17
1.35.0-r18
1
epamedp/edp-admin-console:2.14.0616c678ba3e7
busybox@1.35.0-r17
1.35.0-r18
1
epamedp/jenkins-operator:2.15.328ef56bc0ca3
busybox@1.36.1-r2
1.36.1-r6
1
epamedp/perf-operator:2.13.0bd2079b7bfcb
busybox@1.35.0-r17
1.35.0-r18
1
epamedp/reconciler:2.12.0d33e938b6d59
busybox@1.35.0-r17
1.35.0-r18
1
eqalpha/keydb:alpine_x86_64_v6.3.4f1d60f12cb3c
busybox@1.36.1-r2
1.36.1-r6
1
ethereum/client-go:v1.10.186d6d12a40465
busybox@1.35.0-r13
1.35.0-r18
1
ethereum/client-go:v1.10.23cce21b423165
busybox@1.35.0-r17
1.35.0-r18
1
ethersphere/etherproxy:1.0.056029b0985f4
busybox@1.36.1-r2
1.36.1-r6
1
ethpandaops/blob-me-baby:latestad26158420dd
busybox@1.36.1-r2
1.36.1-r6
1
ethpandaops/blobscan-indexer:latestc58eb9ffe446
busybox@1.35.0-r29
1.35.0-r30
1
evgkrsk/postgres-controller:0.6.237f0e1f435c3
busybox@1.35.0-r29
1.35.0-r30
1
fabioformosa/hello-world-api:latest063873af085c
busybox@1.36.1-r15
1.36.1-r16
1
factly/mande-studio:0.34.19db4bee30e63
busybox@1.35.0-r29
1.35.0-r30
1
factly/mande-web:0.34.1742355964b0e
busybox@1.36.1-r2
1.36.1-r6
1
fallenbagel/jellyseerr:1.7.06dcdb5ba5091
busybox@1.35.0-r17
1.35.0-r18
1
fedodo/fedodo.be.activitypub:14728dada8e3216
busybox@1.35.0-r29
1.35.0-r30
1
fedodo/fedodo.be.auth:208f8eb7a1207e
busybox@1.35.0-r29
1.35.0-r30
1
fedodo/fedodo.ui.home:3c69413c4d690
busybox@1.35.0-r29
1.35.0-r30
1
fedodo/fedodo.ui.micro:12b2b540081c21
busybox@1.35.0-r29
1.35.0-r30
1
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6
1
felddy/foundryvtt:12.343.06c5e3e9ffbb0
busybox@1.36.1-r5
1.36.1-r6
1
felipecs8/app-movies-series:v14e51693fcdf5
busybox@1.35.0-r29
1.35.0-r30
1
felipecs8/qrcode-generator:v1d5f4f17cb066
busybox@1.35.0-r29
1.35.0-r30
1
firefart/requesttracker:nginx-nightly-202307101028236b42a0
busybox@1.35.0-r29
1.35.0-r30
1
fiware/ishare-satellite:1.2.0c3c1c8ccfb45
busybox@1.35.0-r17
1.35.0-r18
1
flanksource/vcluster-sync-host-secrets:v0.1.6bd3294c20a60
busybox@1.36.1-r0
1.36.1-r6
1
flomesh/pipy-repo:0.90.3-3874975c50e3d9
busybox@1.35.0-r15
1.35.0-r18
1
fluidtrendslab/platform:latestbf49de7a4100
busybox@1.35.0-r17
1.35.0-r18
1
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.