Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jpcm-4485-69p7

Опубликовано: 09 мар. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-plugin

Impact

The com.bmuschko:gradle-vagrant-plugin Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables.

When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors.

Patches

Fixed in version 3.0.0

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

com.bmuschko:gradle-vagrant-plugin

maven
Затронутые версииВерсия исправления

>= 0.6, < 3.0.0

3.0.0

EPSS

Процентиль: 31%
0.00119
Низкий

7.4 High

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 5.3
nvd
почти 5 лет назад

The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors. This is fixed in version 3.0.0.

EPSS

Процентиль: 31%
0.00119
Низкий

7.4 High

CVSS3

Дефекты

CWE-532