GHSA-j8mx-j73w-9mxw
LOWCVE-2026-7860A possible information disclosure vulnerability exists in the Vaadin Maven plugin and Vaadin Gradle plugin that exposes the full set of environment variables in build logs whenever the frontend build process exits with a non-zero status. Because the build environment may contain credentials supplied as secrets, any failed frontend build can expose those secrets in clear text in CI logs and archive
- Affected
- >= 23.0.0, < 23.6.10
- Fixed in
- 23.6.11
- Weakness
- CWE-209
- Published
- 2026-05-19
- Source
- github