{"id":"GHSA-jpcm-4485-69p7","summary":"Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-plugin","details":"### Impact\n\nThe `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables.\n\nWhen this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors.\n\n### Patches\nFixed in version 3.0.0\n\n### References\n\n - https://github.com/bmuschko/gradle-vagrant-plugin/blob/292129f9343d00d391543fae06239e9b0f33db73/src/main/groovy/com/bmuschko/gradle/vagrant/process/GDKExternalProcessExecutor.groovy#L42-L44\n - https://github.com/bmuschko/gradle-vagrant-plugin/issues/19\n - https://github.com/bmuschko/gradle-vagrant-plugin/pull/20\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in [bmuschko/gradle-vagrant-plugin](https://github.com/bmuschko/gradle-vagrant-plugin)","aliases":["CVE-2021-21361"],"modified":"2026-07-08T06:29:45.012744188Z","published":"2021-03-09T00:38:41Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-03-09T00:38:15Z","nvd_published_at":"2021-03-09T01:15:00Z","cwe_ids":["CWE-532"]},"references":[{"type":"WEB","url":"https://github.com/JLLeitschuh/security-research/security/advisories/GHSA-jpcm-4485-69p7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-21361"},{"type":"WEB","url":"https://github.com/bmuschko/gradle-vagrant-plugin/issues/19"},{"type":"WEB","url":"https://github.com/bmuschko/gradle-vagrant-plugin/pull/20"},{"type":"WEB","url":"https://github.com/bmuschko/gradle-vagrant-plugin/blob/292129f9343d00d391543fae06239e9b0f33db73/src/main/groovy/com/bmuschko/gradle/vagrant/process/GDKExternalProcessExecutor.groovy#L42-L44"}],"affected":[{"package":{"name":"com.bmuschko:gradle-vagrant-plugin","ecosystem":"Maven","purl":"pkg:maven/com.bmuschko/gradle-vagrant-plugin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.6"},{"fixed":"3.0.0"}]}],"versions":["2.0","2.1","2.2","2.2.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-jpcm-4485-69p7/GHSA-jpcm-4485-69p7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N"}]}