StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
folioci/mod-aes:latest6d67e9564270
busybox@1.35.0-r17
1.35.0-r18
1
folioci/mod-codex-ekb:latest235a3fa4adc9
busybox@1.35.0-r17
1.35.0-r18
1
folioci/mod-codex-inventory:latest6d53ed758fd1
busybox@1.35.0-r17
1.35.0-r18
1
folioci/mod-codex-mux:latestd4138abfd30d
busybox@1.35.0-r17
1.35.0-r18
1
folioci/mod-data-import-converter-storage:latest3028f333778f
busybox@1.35.0-r29
1.35.0-r30
1
foxcpp/maddy:0.7.16ab538e2f28b
busybox@1.36.1-r5
1.36.1-r6
1
fydeinc/envoyproxy:1.13.8.29fadb0a491db
busybox@1.36.1-r2
1.36.1-r6
1
fydeinc/fydeproxy:1.3.1780e7c00bc9e7
busybox@1.36.1-r5
1.36.1-r6
1
galaxy/galaxy-init:v18.010267bad550e6
busybox@1:1.21.0-1ubuntu1
no fix listed
1
galaxy/galaxy-stable:v18.018e577a626dfd
busybox@1:1.21.0-1ubuntu1
no fix listed
1
gcarrarom/landing:0.0.0769d19e441d9
busybox@1.35.0-r17
1.35.0-r18
1
genseb/rabbitmq-producer-randomizer:0.0.6cb7599641099
busybox@1.36.1-r2
1.36.1-r6
1
gitea/gitea:1.21.6ac73e0da341f
busybox@1.36.1-r5
1.36.1-r6
1
glenndehaan/api-mapper:latest6ff6310683bf
busybox@1.36.1-r15
1.36.1-r16
1
glenndehaan/sunflare-tools:latesta5b3f1dd865d
busybox@1.36.1-r0
1.36.1-r6
1
glenndehaan/tesbot:latest372b85ef91eb
busybox@1.36.1-r5
1.36.1-r6
1
goalert/goalert:v0.32.008d57388b0cb
busybox@1.36.1-r15
1.36.1-r16
1
goofball222/pritunl:1.32.3602.807bf26032dfce
busybox@1.35.0-r17
1.35.0-r18
1
grafana/grafana:10.1.50679e877ba20
busybox@1.36.1-r2
1.36.1-r6
1
grafana/grafana:9.4.71a359d92f40e
busybox@1.35.0-r29
1.35.0-r30
1
grafana/grafana:10.1.11b9ca4bbc4a2
busybox@1.36.1-r2
1.36.1-r6
1
grafana/grafana:9.5.239c849cebccc
busybox@1.35.0-r29
1.35.0-r30
1
grafana/grafana:10.2.36b5b37eb35bb
busybox@1.36.1-r2
1.36.1-r6
1
grafana/grafana:10.3.38640e5038e83
busybox@1.36.1-r2
1.36.1-r6
1
grafana/grafana:11.1.3b23b588cf7cb
busybox@1.36.1-r15
1.36.1-r16
1
grafana/grafana:10.4.0f9811e4e687f
busybox@1.36.1-r15
1.36.1-r16
1
grafana/loki:2.9.26074e01dbe03
busybox@1.36.1-r2
1.36.1-r6
1
grafana/loki:2.9.66ca6e2cd3b6f
busybox@1.36.1-r5
1.36.1-r6
1
grafana/loki:3.0.0757b5fadf816
busybox@1.36.1-r5
1.36.1-r6
1
grafana/loki:2.8.2b1da1d23037e
busybox@1.35.0-r17
1.35.0-r18
1
grafana/loki-canary:3.0.028d7c00588aa
busybox@1.36.1-r5
1.36.1-r6
1
grafana/loki-canary:3.1.039baf6d67f85
busybox@1.36.1-r5
1.36.1-r6
1
grafana/loki-canary:2.9.24249db29b992
busybox@1.36.1-r2
1.36.1-r6
1
grafana/loki-canary:2.9.6549a40203e97
busybox@1.36.1-r5
1.36.1-r6
1
grafana/mimir:r292-5f018727476e456c738
busybox@1.36.1-r15
1.36.1-r16
1
grafana/phlare:0.5.1330f990cdad9
busybox@1.35.0-r17
1.35.0-r18
1
grafana/rollout-operator:v0.14.03409edfb45c7
busybox@1.36.1-r15
1.36.1-r16
1
gresearchdev/siembol-config-editor-ui:latest071e7109a981
busybox@1.35.0-r17
1.35.0-r18
1
gresearch/fasttrackml:latest16d1228220fc
busybox@1.36.1-r15
1.36.1-r16
1
groundnuty/k8s-wait-for:no-root-v2.0a26d3d3f6e1c
busybox@1.35.0-r17
1.35.0-r18
1
guacamole/guacd:1.5.538232cae2713
busybox@1.36.1-r5
1.36.1-r6
1
gutmensch/podnat-controller:0.5.2566979793fc4
busybox@1.36.1-r5
1.36.1-r6
1
hamid2021/nodejs-dockercli:latest429d99890c3c
busybox@1.35.0-r29
1.35.0-r30
1
hansehe/graphql-gateway:1.0.458e09540afbc
busybox@1.36.1-r2
1.36.1-r6
1
haproxytech/haproxy-alpine:2.9.57f3dc8c7e031
busybox@1.36.1-r5
1.36.1-r6
1
haproxytech/haproxy-alpine:2.8.08951be4b4e1c
busybox@1.36.1-r0
1.36.1-r6
1
haproxytech/kubernetes-ingress:1.11.4c5f8a41ef0d4
busybox@1.36.1-r5
1.36.1-r6
1
hashicorp/boundary:0.15.3339b78b61750
busybox@1.36.1-r5
1.36.1-r6
1
hashicorp/consul:1.17.0712fe02d2f84
busybox@1.36.1-r2
1.36.1-r6
1
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.