Medium severity5.3NVD Advisory· Published Mar 9, 2021· Updated Jun 17, 2026
CVE-2021-21361
CVE-2021-21361
Description
The com.bmuschko:gradle-vagrant-plugin Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plugin is executed in public CI/CD, this can lead to sensitive credentials being exposed to malicious actors. This is fixed in version 3.0.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.bmuschko:gradle-vagrant-pluginMaven | >= 0.6, < 3.0.0 | 3.0.0 |
Affected products
3- JLLeitschuh/security-researchv5Range: < 3.0.0
Patches
Vulnerability mechanics
References
6- github.com/bmuschko/gradle-vagrant-plugin/issues/19nvdPatchThird Party AdvisoryWEB
- github.com/bmuschko/gradle-vagrant-plugin/pull/20nvdPatchThird Party AdvisoryWEB
- github.com/JLLeitschuh/security-research/security/advisories/GHSA-jpcm-4485-69p7nvdExploitThird Party AdvisoryWEB
- github.com/bmuschko/gradle-vagrant-plugin/blob/292129f9343d00d391543fae06239e9b0f33db73/src/main/groovy/com/bmuschko/gradle/vagrant/process/GDKExternalProcessExecutor.groovynvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-jpcm-4485-69p7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-21361ghsaADVISORY
News mentions
0No linked articles in our index yet.