CVE-2021-3040 MEDIUM

CVE-2021-3040: Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution

Vendor Palo Alto Networks
Product Bridgecrew Checkov
Weakness CWE-502 · Unsafe deserialization
Published June 10, 2021
Last update September 16, 2024

CVSS base score

6.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.

Key dates

02Disclosure timeline

June 10, 2021 CVE published
September 16, 2024 Record updated