An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.
Fixes

Solution

This issue is fixed in Checkov 2.0.139 and all later versions.


Workaround

Do not run Checkov on terraform files from untrusted sources or pull requests.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: palo_alto

Published:

Updated: 2024-09-16T18:23:39.787Z

Reserved: 2021-01-06T00:00:00

Link: CVE-2021-3040

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-10T13:15:08.343

Modified: 2024-11-21T06:20:49.213

Link: CVE-2021-3040

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.