Vagrant Project maintains a widely used infrastructure-automation and development-environment tool that abstracts virtual machine provisioning and configuration across multiple hypervisors and cloud platforms. The product's durable vulnerability signal centers on improper handling of sensitive information in log files, a weakness class relevant to a tool that captures and outputs detailed system state and credential data during provisioning workflows. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vagrant Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21361MEDIUM The `com.bmuschko:gradle-vagrant-plugin` Gradle plugin contains an information disclosure vulnerability due to the logging of the system environment variables. When this Gradle plu | Mar 9, 2021 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vagrant Project.
Media articles that mention a CVE ID that affects a product developed by Vagrant Project — matched by CVE ID, not by vendor name.