Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-plugin
High severity
GitHub Reviewed
Published
Mar 8, 2021
in
JLLeitschuh/security-research
•
Updated Feb 1, 2023
Package
Affected versions
>= 0.6, < 3.0.0
Patched versions
3.0.0
Description
Reviewed
Mar 9, 2021
Published to the GitHub Advisory Database
Mar 9, 2021
Published by the National Vulnerability Database
Mar 9, 2021
Last updated
Feb 1, 2023
Impact
The
com.bmuschko:gradle-vagrant-plugin
Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables.When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors.
Patches
Fixed in version 3.0.0
References
For more information
If you have any questions or comments about this advisory:
References