Description
A sensitive information disclosure vulnerability in Palo Alto Networks Checkov by Prisma® Cloud can result in the cleartext exposure of Prisma Cloud access keys in Checkov's output.
Attacker finds a Prisma Cloud access key in a Checkov output file that a user uploaded to an insecure location.
Attacker gains access to a system and then finds a Checkov output file that contains an exposed Prisma Cloud access key.
Problem types
CWE-312 Cleartext Storage of Sensitive Information
Product status
3.2.0 before 3.2.449
Timeline
2025-08-13: | Initial Publication |
Credits
Shashank Chaurasia
References
security.paloaltonetworks.com/CVE-2025-2181