CVE-2021-3035 MEDIUM

CVE-2021-3035: Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution

Vendor Palo Alto Networks
Product Bridgecrew Checkov
Weakness CWE-502 · Unsafe deserialization
Published April 20, 2021
Last update September 17, 2024

CVSS base score

6.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.26. Checkov 1.0 versions are not impacted.

Key dates

02Disclosure timeline

April 20, 2021 CVE published
September 17, 2024 Record updated

Related vulnerabilities

04Related CVE