Description
The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors. This is fixed in version 3.0.0.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-0678 | The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors. This is fixed in version 3.0.0. |
Github GHSA |
GHSA-jpcm-4485-69p7 | Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-plugin |
References
History
No history.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-03T18:09:15.934Z
Reserved: 2020-12-22T00:00:00.000Z
Link: CVE-2021-21361
No data.
Status : Modified
Published: 2021-03-09T01:15:13.230
Modified: 2024-11-21T05:48:11.877
Link: CVE-2021-21361
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA