StackRadar

CVE-2023-42366

Medium

Advisory

Published 27 Nov 2023In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.5
base score, highest
EPSS
0.004
35th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
807
of 17,787 indexed, latest versions
Container images
844
deployed by those charts
Fix available
1 of 2
affected packages

The matching OSV records carry no description.

Carried by container images the latest versions of 807 of 17,787 indexed charts deploy, on 844 images.

Affected packageAffected versionsFixed inImages
busyboxapk1.35.0-r10, 1.35.0-r13, 1.35.0-r14, 1.35.0-r15+10 more1.35.0-r18, 1.35.0-r30, 1.36.1-r6, 1.36.1-r16+1 more819
busyboxdeb1:1.21.0-1ubuntu1, 1:1.21.0-1ubuntu1.4, 1:1.30.1-4ubuntu6.4, 1:1.30.1-7ubuntu3+6 moreno fix listed25
OSV records
ALPINE-CVE-2023-42366DEBIAN-CVE-2023-42366UBUNTU-CVE-2023-42366

Charts affected

807 by stars
ChartLatestAffected imagesRadar Score
prometheusalertygqygq2Verified publisher1.0.01 of 1See more

prometheusalert ygqygq2 1.0.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
feiyu563/prometheus-alert:v4.9.1224cfa68cbd9
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,611
rawfile-csiymatrixVerified publisher0.2.11 of 4See more

rawfile-csi ymatrix 0.2.1

1 of the 4 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
matrixdb/rawfile-csi:v0.2.195b2e38e913d
busybox@1.35.0-r10
1.35.0-r18

Open the chart page →

7,972
zahori-consulzahoriVerified publisher1.0.12 of 2See more

zahori-consul zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
hashicorp/consul:1.15.3ddff34041c5c
busybox@1.35.0-r29
1.35.0-r30
hashicorp/consul-k8s-control-plane:1.1.262bed1bf8106
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,033
zahori-postgresqlzahoriVerified publisher1.0.11 of 1See more

zahori-postgresql zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
library/postgres:12.15-alpine73ea9cdd4a9d
busybox@1.36.1-r2
1.36.1-r6

Open the chart page →

448
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
busybox@1.36.1-r0
1.36.1-r6

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.12 of 2See more

zahori-server zahori 1.0.1

2 of the 2 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
flyway/flyway:9.14.1-alpine80f12c80502b
busybox@1.35.0-r29
1.35.0-r30
zahoriaut/zahori-server:0.1.17b2de13916f3e
busybox@1.35.0-r29
1.35.0-r30

Open the chart page →

5,846
sockpuppetbrowserzekker6Verified publisher0.1.01 of 1See more

sockpuppetbrowser zekker6 0.1.0

1 of the 1 container images this version deploys carry CVE-2023-42366.

Container imageDigestPackageFixed in
dgtlmoon/sockpuppetbrowser:latestf166a963b550
busybox@1.36.1-r5
1.36.1-r6

Open the chart page →

1,589

Container images carrying it

844 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
pnnlmiscscripts/anaconda:20201029-1700-nginx-105827b9efa7b
busybox@1.35.0-r17
1.35.0-r18
10
curlimages/curl:8.5.008e466006f08
busybox@1.36.1-r15
1.36.1-r16
7
library/registry:2.8.1dbaa3e69f563
busybox@1.36.0-r9
1.36.1-r6
6
quay.io/devtron/kubectl:latest2ad610626658
busybox@1.35.0-r17
1.35.0-r18
6
quay.io/devtron/migrator:v4.16.2fbeaef7a8566
busybox@1.36.0-r9
1.36.1-r6
6
natsio/nats-box:0.14.1a67913df95f1
busybox@1.36.1-r4
1.36.1-r6
5
ghcr.io/conductionnl/commonground-gateway-nginx:latestb72cf734d85f
busybox@1.36.1-r5
1.36.1-r6
5
ghcr.io/conductionnl/commonground-gateway-php:latest947882bf2c37
busybox@1.35.0-r17
1.35.0-r18
5
curlimages/curl:7.87.0:multiarch-7.87.0f7f265d5c64e
busybox@1.35.0-r17
1.35.0-r18
4
hyperledger/fabric-orderer:2.46ec3fe59ea55
busybox@1.35.0-r17
1.35.0-r18
4
hyperledger/fabric-peer:2.46ff36af21eb1
busybox@1.35.0-r17
1.35.0-r18
4
hyperledger/fabric-tools:2.4b1194f509085
busybox@1.35.0-r17
1.35.0-r18
4
jaegertracing/jaeger-agent:1.53.00214a0ef24b1
busybox@1.35.0-r17
1.35.0-r18
4
jaegertracing/jaeger-collector:1.53.07f1269222903
busybox@1.35.0-r17
1.35.0-r18
4
jaegertracing/jaeger-query:1.53.0049bb0d64ea3
busybox@1.35.0-r17
1.35.0-r18
4
rss3/op-geth:rss3-main-1ecad3026148aa1bc52
busybox@1.36.1-r15
1.36.1-r16
4
ghcr.io/loft-sh/vcluster-pro:0.0.0-ci-run.10ab2e1fa19dd4
busybox@1.36.1-r0
1.36.1-r6
4
ghcr.io/skooner-k8s/skooner:stable60c1562e4d51
busybox@1.36.1-r2
1.36.1-r6
4
alfhou/hammond:v0.0.24c85dc0293aa1
busybox@1.36.1-r15
1.36.1-r16
3
caddy/ingress:v0.2.118d1366fc0e9
busybox@1.36.1-r2
1.36.1-r6
3
getmeili/meilisearch:v1.7.319b825993dbe
busybox@1.35.0-r17
1.35.0-r18
3
grafana/grafana:11.0.00dc5a246ab16
busybox@1.36.1-r15
1.36.1-r16
3
groundnuty/k8s-wait-for:v2.0c14d7271e401
busybox@1.35.0-r17
1.35.0-r18
3
library/docker:20.10-dind:20-dindaf96c680a7e1
busybox@1.36.0-r9
1.36.1-r6
3
library/nginx:1.25.5-alpine:1.25-alpine516475cc129d
busybox@1.36.1-r15
1.36.1-r16
3
library/postgres:10-alpine63cfb6eac6b3
busybox@1.35.0-r17
1.35.0-r18
3
library/redis:7.2.4-alpinec8bb255c3559
busybox@1.36.1-r15
1.36.1-r16
3
natsio/nats-server-config-reloader:0.13.0b3359eeb10bf
busybox@1.36.1-r0
1.36.1-r6
3
nginxinc/nginx-unprivileged:1.24-alpinebe76a26e238d
busybox@1.36.1-r5
1.36.1-r6
3
oryd/hydra:v2.2.02c93beb5e5f2
busybox@1.36.1-r5
1.36.1-r6
3
paulkellerman/resultserver-app:1.0381eeccb0618
busybox@1.35.0-r17
1.35.0-r18
3
paulkellerman/webserver-app:latest5a37b74f61b9
busybox@1.35.0-r17
1.35.0-r18
3
pnnlmiscscripts/anaconda9:1683907016.7470503-nginx-19a2fe06a1472
busybox@1.35.0-r29
1.35.0-r30
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
busybox@1.36.1-r5
1.36.1-r6
3
rss3/op-node:d2c5ced00901227473fc196fda838191f0cb4e02d1d2ae6efd05
busybox@1.36.1-r5
1.36.1-r6
3
tykio/tyk-gateway-ee:v5.13.13e907e675bf9
busybox@1:1.37.0-6+dhi1
no fix listed
3
quay.io/devtron/argocd-cert-refresh:v102b6db27eaf3d
busybox@1:1.30.1-7ubuntu3
no fix listed
3
quay.io/devtron/devtron-utils:geni-v1.1.4f6269309455a
busybox@1.36.1-r15
1.36.1-r16
3
quay.io/devtron/jcmhproxy-ingress:v0.14.64286bcccda3e
busybox@1.36.1-r15
1.36.1-r16
3
quay.io/devtron/kubewatch:49f906a5-419-14814eec0305b594c
busybox@1.36.1-r2
1.36.1-r6
3
quay.io/devtron/nats:2.9.3-alpinef0cf3c3ab495
busybox@1.35.0-r17
1.35.0-r18
3
quay.io/devtron/nats-box:latest48cdd3054b20
busybox@1.35.0-r17
1.35.0-r18
3
quay.io/devtron/svn-git-sync:v78e54bc2d261f
busybox@1.35.0-r13
1.35.0-r18
3
quay.io/jupyterhub/configurable-http-proxy:4.6.1fd916f75415f
busybox@1.36.1-r5
1.36.1-r6
3
quay.io/metallb/controller:v0.13.101b33357b3595
busybox@1.36.0-r9
1.36.1-r6
3
registry.k8s.io/ingress-nginx/controller:v1.5.14ba73c697770
busybox@1.35.0-r17
1.35.0-r18
3
registry.k8s.io/ingress-nginx/controller:v1.8.1e5c4824e7375
busybox@1.36.1-r0
1.36.1-r6
3
agoldis/sorry-cypress-api:2.5.11afaa5a84051d
busybox@1.36.1-r2
1.36.1-r6
2
agoldis/sorry-cypress-dashboard:2.5.11e061e5714238
busybox@1.35.0-r29
1.35.0-r30
2
agoldis/sorry-cypress-director:2.5.1110228ecd353b
busybox@1.36.1-r2
1.36.1-r6
2

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.