StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
813
of 17,787 indexed, latest versions
Container images
851
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 813 of 17,787 indexed charts deploy, on 851 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more825
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed26
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

813 by stars
ChartLatestAffected imagesRadar Score
owlxdVerified publisher0.5.12 of 2See more

owl xd 0.5.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/owl-console:v0.11.2c79a67657baf
busybox@1.35.0-r29
1.35.0-r30
lishimeng/owl-messager:v0.11.23d00485e64dc
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,880
passportxdVerified publisher0.2.162 of 2See more

passport xd 0.2.16

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/passport:v0.2.163e7d05ded625
busybox@1.35.0-r29
1.35.0-r30
lishimeng/passport-profile:v0.2.160970dfe5dc8f
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

3,974
tabbyxdVerified publisher1.0.61 of 2See more

tabby xd 1.0.6

1 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tabby:v1.0.48145c3dc83c8
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

7,685
treexdVerified publisher0.1.101 of 1See more

tree xd 0.1.10

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/tree:v0.2.89b2f8be6c7d3
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,997
zooxdVerified publisher0.4.01 of 1See more

zoo xd 0.4.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
lishimeng/zoo:v0.4.0e0b8d2d8ca28
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

1,955
pgbounceryasn77-pgbouncer0.0.81 of 1See more

pgbouncer yasn77-pgbouncer 0.0.8

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
ghcr.io/yasn77/pgbouncer:v0.0.6cc8c13550e44
busybox@1.35.0-r17
1.35.0-r18

Open the chart page →

1,152
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,610
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,847
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,588

Container images carrying it

851 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
kfirfer/slackgpt:0.0.15461331bd838e
busybox@1.36.1-r2
1.36.1-r6
1
kiwigrid/k8s-sidecar:1.26.2e271016441af
busybox@1.36.1-r15
1.36.1-r16
1
ktitilayo2/nodejswebapp:latest8bac28058688
busybox@1.35.0-r29
1.35.0-r30
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
busybox@1.36.1-r0
1.36.1-r6
1
kubebb/component-store:latestfd8ecbd73213
busybox@1.36.1-r0
1.36.1-r6
1
kubebb/ingress-nginx-controller:v1.3.0067673df26a6
busybox@1.35.0-r14
1.35.0-r18
1
kubebb/mesh-operator:v5.7.0163ebbfc7a82
busybox@1.36.1-r0
1.36.1-r6
1
kubeflownotebookswg/centraldashboard:v1.9.2af55c22ef5de
busybox@1.36.1-r2
1.36.1-r6
1
kubegems/alertproxy:v0.4.2eaee03055329
busybox@1.35.0-r17
1.35.0-r18
1
kubegems/chatgpt-api-feishubot:latest7c93c84b2055
busybox@1.35.0-r29
1.35.0-r30
1
kubegems/chatgpt-api-proxy:latest8905c9dbbb5d
busybox@1.35.0-r29
1.35.0-r30
1
kubegems/kubectl:latestc3b4be9a54f5
busybox@1.35.0-r29
1.35.0-r30
1
kubesec/kubesec:v2.13.0c0f3b0673578
busybox@1.35.0-r29
1.35.0-r30
1
kubeshop/kusk-gateway-dashboard:v1.2.6ff9b5aa1258d
busybox@1.35.0-r17
1.35.0-r18
1
kubeshop/testkube-dashboard:1.16.748958b4126a4
busybox@1.36.1-r5
1.36.1-r6
1
kubesphere/ks-extensions-museum:latest29681958f220
busybox@1.36.1-r15
1.36.1-r16
1
kubestar/event-exporter:latest656606941255
busybox@1.36.1-r5
1.36.1-r6
1
kubesuite/kubereport:latest0262424ee702
busybox@1.36.0-r9
1.36.1-r6
1
kubevious/backend:1.2.22d9ba6eb46b6
busybox@1.36.1-r15
1.36.1-r16
1
kubevious/collector:1.2.1f58226f9d84e
busybox@1.36.1-r0
1.36.1-r6
1
kubevious/guard:1.2.19bf567704de2
busybox@1.35.0-r29
1.35.0-r30
1
kubevious/parser:1.0.151acf1a1f0b47
busybox@1.35.0-r17
1.35.0-r18
1
kubevious/parser:1.2.299ae7a5168c2
busybox@1.36.1-r15
1.36.1-r16
1
kubevious/ui:1.2.16233e84bdd59
busybox@1.35.0-r17
1.35.0-r18
1
kubevious/workload-operator:1.0.20b0f4c507eb6
busybox@1.35.0-r29
1.35.0-r30
1
kubevirtmanager/kubevirt-manager:1.3.3df3ea27d4a9e
busybox@1.36.1-r5
1.36.1-r6
1
kupnu4x/kube-vault-controller:1.2.03be59109f3d6
busybox@1.35.0-r17
1.35.0-r18
1
kusionstack/karpor:v0.6.4b707d3bf0abd
busybox@1.35.0-r29
1.35.0-r30
1
kvalitetsit/metadoc-app:maine89e351733ad
busybox@1.35.0-r29
1.35.0-r30
1
kvalitetsit/stakit-frontend:0.2.5fd5c4f60ef80
busybox@1.35.0-r29
1.35.0-r30
1
kyleslugg/klusterview:latestba8c36dfdfbd
busybox@1.35.0-r29
1.35.0-r30
1
kyso/imagebox:latest68091eace89c
busybox@1.35.0-r29
1.35.0-r30
1
kyso/jupyter-diff:latest82299a9e5a86
busybox@1.35.0-r29
1.35.0-r30
1
kyso/kyso-front:lateste52595c5c16f
busybox@1.35.0-r13
1.35.0-r18
1
kyso/kyso-nbdime:latest4aa9d38ee81d
busybox@1.35.0-r29
1.35.0-r30
1
lachlanevenson/k8s-kubectl:v1.22.1638b7962cd016
busybox@1.35.0-r29
1.35.0-r30
1
laly9999/node-app-dockerized:latest75ae77a20c6c
busybox@1.35.0-r29
1.35.0-r30
1
langgenius/dify-web:0.6.11a2a294743634
busybox@1.36.1-r15
1.36.1-r16
1
lavandadelpatio/tmdb:latestded9377636e9
busybox@1.36.1-r2
1.36.1-r6
1
lavandadelpatio/torznab-atomohd:latest214eaef5444c
busybox@1.35.0-r29
1.35.0-r30
1
library/alpine:3.18.002bb6f428431
busybox@1.36.0-r9
1.36.1-r6
1
library/alpine:3.18.282d1e9d7ed48
busybox@1.36.1-r0
1.36.1-r6
1
library/bash:5.2.21a422913be6a4
busybox@1.36.1-r15
1.36.1-r16
1
library/caddy:2.660fb54d36b4b
busybox@1.35.0-r17
1.35.0-r18
1
library/docker:24.0.2-dind1d148deae16a
busybox@1.36.1-r0
1.36.1-r6
1
library/docker:20.10.21-dind3153fa63f546
busybox@1.35.0-r29
1.35.0-r30
1
library/docker:23.0.6-dindafa5d5134900
busybox@1.36.1-r2
1.36.1-r6
1
library/docker:23.0.1-dindd9a0fd8bdd15
busybox@1.35.0-r29
1.35.0-r30
1
library/eclipse-mosquitto:2.0.15bbac73a740f4
busybox@1.36.1-r2
1.36.1-r6
1
library/haproxy:2.2-alpine20d5eaf7187e
busybox@1.35.0-r17
1.35.0-r18
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.