Description
An unsafe deserialization vulnerability in Palo Alto Networks Checkov by Prisma® Cloud allows an authenticated user to execute arbitrary code as a non administrative user by scanning a malicious terraform file when using Checkov in Prisma® Cloud. This issue impacts Checkov 3.0 versions earlier than Checkov 3.2.415.
If the user scans infrastructure as code (IaC) files from untrusted sources.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
3.2.0 before 3.2.415
Timeline
2025-08-13: | Initial publication |
Credits
Palo Alto Networks thanks Bryan Eastes for discovering and reporting this issue.
References
security.paloaltonetworks.com/CVE-2025-2180