StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
hashicorp/consul-k8s-control-plane:1.3.00e4452f0f265
busybox@1.36.1-r2
1.36.1-r6
1
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30
1
hashicorp/terraform:1.44dcb45513699
busybox@1.36.1-r2
1.36.1-r6
1
hashicorp/terraform-k8s:1.1.2b19857bab620
busybox@1.35.0-r13
1.35.0-r18
1
hashicorp/vault:1.15.40b01ed3924e6
busybox@1.36.1-r5
1.36.1-r6
1
hashicorp/vault-k8s:1.2.14500e988b7ce
busybox@1.35.0-r29
1.35.0-r30
1
hashicorp/waypoint:0.11.397d521a27498
busybox@1.35.0-r29
1.35.0-r30
1
hazelcast/hazelcast:5.3.18fe26efde8e1
busybox@1.36.1-r2
1.36.1-r6
1
hetznercloud/hcloud-cloud-controller-manager:v1.16.08c07e6d7a76c
busybox@1.36.1-r0
1.36.1-r6
1
hiett/serverless-redis-http:0.0.1065128347949b
busybox@1.35.0-r29
1.35.0-r30
1
hiett/serverless-redis-http:0.0.485cdc5801e66
busybox@1.35.0-r17
1.35.0-r18
1
hngtech11/hello-world:v1f0112dc12cfb
busybox@1.36.1-r5
1.36.1-r6
1
holiman/nodemonitor:latest5cd609761065
busybox@1.35.0-r17
1.35.0-r18
1
homeassistant/home-assistant:2023.10.3021e2afc6e57
busybox@1.36.1-r2
1.36.1-r6
1
homeassistant/home-assistant:2023.12.48d000332b09b
busybox@1.36.1-r2
1.36.1-r6
1
huajuan6848/sys-info-web:0.0.2-SNAPSHOT-HEALTH0a9f0a692dc4
busybox@1.36.1-r2
1.36.1-r6
1
hyperized/pgbouncer:v1.21.06f64ca124fb5
busybox@1.36.1-r2
1.36.1-r6
1
hyperledgerk8s/bc-explorer:v202305041f1a06b61f18
busybox@1.35.0-r17
1.35.0-r18
1
hyperledgerk8s/bc-saas:v0.0.1-20230524d8bc31176257
busybox@1.35.0-r17
1.35.0-r18
1
i4trust/activation-service:2.2.09f3719176893
busybox@1.36.1-r0
1.36.1-r6
1
imroc/logrotate:3.21.0135c769e659f
busybox@1.36.1-r15
1.36.1-r16
1
invisibl/identity-manager:1.0.01029f4fe20eb
busybox@1.35.0-r13
1.35.0-r18
1
invoiceninja/invoiceninja:5.6.241437916dee01
busybox@1.36.1-r0
1.36.1-r6
1
iomesh/blockdevice-monitor:v0.2.1376577ed98ac
busybox@1.35.0-r29
1.35.0-r30
1
iomesh/blockdevice-monitor:v0.1.0d86dab5611a7
busybox@1.35.0-r29
1.35.0-r30
1
iomesh/blockdevice-monitor-prober:v0.2.1026a1d87f6e9
busybox@1.35.0-r29
1.35.0-r30
1
iomesh/blockdevice-monitor-prober:v0.1.0584dbe19db7e
busybox@1.35.0-r29
1.35.0-r30
1
iomesh/deck:v0.1.0a31e26b6ae22
busybox@1.36.1-r15
1.36.1-r16
1
iomesh/deck-plugin-iomesh:v0.1.00b13bf217110
busybox@1.36.1-r15
1.36.1-r16
1
iomesh/prepare-csi:v1.0.3-rc0063b18afb6a1
busybox@1.36.1-r0
1.36.1-r6
1
iomesh/prepare-csi:v1.0.24206d42b92f1
busybox@1.36.1-r0
1.36.1-r6
1
irakli/ms-hello-python:latest9e7a91ba9ae0
busybox@1.35.0-r17
1.35.0-r18
1
j4ckhunter/consumer:1.00bb7a429e3e75
busybox@1.35.0-r17
1.35.0-r18
1
j4ckhunter/producer:1.006ba447609b12
busybox@1.35.0-r17
1.35.0-r18
1
jaegertracing/all-in-one:1.53.060e65bfffe1f
busybox@1.35.0-r17
1.35.0-r18
1
jaegertracing/all-in-one:1.42.07d32a4eddec7
busybox@1.35.0-r17
1.35.0-r18
1
jaegertracing/all-in-one:1.55f6b5d09073f1
busybox@1.35.0-r17
1.35.0-r18
1
jaegertracing/jaeger-collector:1.41.0ff81f0a9f63c
busybox@1.35.0-r17
1.35.0-r18
1
jaegertracing/jaeger-query:1.41.0b636f0f464bc
busybox@1.35.0-r17
1.35.0-r18
1
jlesage/handbrake:v24.01.20752dcb72bd1
busybox@1.35.0-r29
1.35.0-r30
1
jlesage/jdownloader-2:v24.01.1b020fd3132a1
busybox@1.35.0-r17
1.35.0-r18
1
josepht05/nodejs-feb24:latest36cb0c618c94
busybox@1.35.0-r29
1.35.0-r30
1
josepht05/titajo-docker:v1.0.0d94024965d78
busybox@1.35.0-r29
1.35.0-r30
1
juicedata/csi-dashboard:v0.23.03e4daf9626d5
busybox@1.36.1-r2
1.36.1-r6
1
jupyterhub/configurable-http-proxy:4.5.67adeeed34a36
busybox@1.36.1-r2
1.36.1-r6
1
jupyterhub/configurable-http-proxy:4.5.39e2c0107c7a3
busybox@1.35.0-r17
1.35.0-r18
1
jupyterhub/k8s-network-tools:3.0.1-0.dev.git.6287.hbfb05cd691f8f833fc1d
busybox@1.36.1-r2
1.36.1-r6
1
kfirfer/gcloud-mysql:1.0.3c257c1e0e8b9
busybox@1.36.1-r5
1.36.1-r6
1
kfirfer/king:latestc05d9fc7ae77
busybox@1.35.0-r29
1.35.0-r30
1
kfirfer/mysql-client:0.0.4d23d173f333f
busybox@1.36.1-r15
1.36.1-r16
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.