CVE-2021-3040Medium

CVE-2021-3040 Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution

Published
June 9, 2021
Last Modified
June 9, 2021

🔗 CVE IDs covered (1)

📋 Description

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.

🎯 Affected products1

  • Bridgecrew Checkov

✅ Remediation

This issue is fixed in Checkov 2.0.139 and all later versions. Workarounds and mitigations: Do not run Checkov on terraform files from untrusted sources or pull requests.

🔗 References (1)