The com.bmuschko:gradle-vagrant-plugin
Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables.
When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors.
Fixed in version 3.0.0
If you have any questions or comments about this advisory: * Open an issue in bmuschko/gradle-vagrant-plugin
{ "nvd_published_at": "2021-03-09T01:15:00Z", "github_reviewed_at": "2021-03-09T00:38:15Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-532" ] }