Palo Alto Networks Checkov by Prisma Cloud Unsafe Deserialization Vulnerability Allows Arbitrary Code Execution
Vulnerability
A vulnerability allowing unsafe deserialization has been identified in Palo Alto Networks Checkov by Prisma Cloud. This issue allows an authenticated user to execute arbitrary code as a non-administrative user. The vulnerability arises when Checkov scans a malicious Terraform file from untrusted sources. It affects Checkov versions 3.2.0 prior to 3.2.415.
Impact
Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code.
Remediation
Users are advised to upgrade to Checkov version 3.2.415 or later. Additionally, it is recommended not to run Checkov on Terraform files from untrusted sources or pull requests.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
