This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.
No analysis available yet.
Vendor Workaround
Do not run Checkov on terraform files from untrusted sources or pull requests.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-24606 | An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415. |
| Link | Providers |
|---|---|
| https://security.paloaltonetworks.com/CVE-2025-2180 |
|
Fri, 15 Aug 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paloaltonetworks
Paloaltonetworks checkov |
|
| Vendors & Products |
Paloaltonetworks
Paloaltonetworks checkov |
Wed, 13 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415. | |
| Title | Checkov by Prisma Cloud: Unsafe Deserialization of Terraform Files Allows Code Execution | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: palo_alto
Published:
Updated: 2025-08-13T17:21:30.216Z
Reserved: 2025-03-10T17:56:22.502Z
Link: CVE-2025-2180
Updated: 2025-08-13T17:21:25.289Z
Status : Awaiting Analysis
Published: 2025-08-13T17:15:25.973
Modified: 2025-08-13T17:33:46.673
Link: CVE-2025-2180
No data.
OpenCVE Enrichment
Updated: 2025-08-14T12:59:57Z
EUVD