CVE-2021-3040

Source
https://cve.org/CVERecord?id=CVE-2021-3040
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3040.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-3040
Aliases
Published
2021-06-10T13:15:08.343Z
Modified
2026-02-09T12:26:36.379260Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.

References

Affected packages

Git / github.com/bridgecrewio/checkov

Affected ranges

Type
GIT
Repo
https://github.com/bridgecrewio/checkov
Events

Affected versions

2.*
2.0.0
2.0.1
2.0.10
2.0.100
2.0.101
2.0.102
2.0.103
2.0.104
2.0.105
2.0.106
2.0.107
2.0.108
2.0.109
2.0.11
2.0.110
2.0.111
2.0.112
2.0.113
2.0.114
2.0.115
2.0.116
2.0.117
2.0.118
2.0.119
2.0.12
2.0.120
2.0.121
2.0.122
2.0.123
2.0.124
2.0.125
2.0.126
2.0.127
2.0.128
2.0.129
2.0.13
2.0.130
2.0.131
2.0.132
2.0.133
2.0.134
2.0.135
2.0.136
2.0.137
2.0.138
2.0.14
2.0.15
2.0.16
2.0.17
2.0.18
2.0.19
2.0.2
2.0.20
2.0.21
2.0.22
2.0.23
2.0.24
2.0.25
2.0.26
2.0.27
2.0.28
2.0.29
2.0.3
2.0.30
2.0.31
2.0.32
2.0.33
2.0.34
2.0.35
2.0.36
2.0.37
2.0.38
2.0.39
2.0.4
2.0.40
2.0.41
2.0.42
2.0.43
2.0.44
2.0.45
2.0.46
2.0.47
2.0.48
2.0.49
2.0.5
2.0.50
2.0.51
2.0.52
2.0.53
2.0.54
2.0.55
2.0.56
2.0.57
2.0.58
2.0.59
2.0.6
2.0.60
2.0.61
2.0.62
2.0.63
2.0.64
2.0.65
2.0.66
2.0.67
2.0.68
2.0.69
2.0.7
2.0.70
2.0.71
2.0.72
2.0.73
2.0.74
2.0.75
2.0.76
2.0.77
2.0.78
2.0.79
2.0.8
2.0.80
2.0.81
2.0.82
2.0.83
2.0.84
2.0.85
2.0.86
2.0.87
2.0.88
2.0.89
2.0.9
2.0.90
2.0.91
2.0.92
2.0.93
2.0.94
2.0.95
2.0.96
2.0.97
2.0.98
2.0.99

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3040.json"