Severity
7.5HIGH
EPSS
0.3%
top 45.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 20
Latest updateMay 24

Description

InstallBuilder AutoUpdate tool and regular installers enabling built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDvmware/installbuilder< 19.11.0
CVEListV5vmware/installbuilderAll versions prior to version 19.11.0

🔴Vulnerability Details

2
GHSA
GHSA-x6rx-7hmf-r792: InstallBuilder AutoUpdate tool and regular installers enabling built with versions earlier than 192022-05-24
CVEList
CVE-2020-3946: InstallBuilder AutoUpdate tool and regular installers enabling built with versions earlier than 192020-04-20
CVE-2020-3946 (HIGH CVSS 7.5) | InstallBuilder AutoUpdate tool and | cvebase.io