An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.
Fixes

Solution

This issue is fixed in Checkov 2.0.26 and all later releases.


Workaround

Do not run Checkov on terraform files from untrusted sources or pull requests.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2024-09-17T03:17:34.411Z

Reserved: 2021-01-06T00:00:00

Link: CVE-2021-3035

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-20T04:15:12.340

Modified: 2024-11-21T06:20:48.377

Link: CVE-2021-3035

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.