The com.bmuschko:gradle-vagrant-plugin Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors. This is fixed in version 3.0.0.
| Software | From | Fixed in |
|---|---|---|
| vagrant_project / vagrant | - | 0.6 |
| vagrant_project / vagrant | 2.0 | 3.0.0 |
com.bmuschko / gradle-vagrant-plugin
|
0.6 | 3.0.0 |