s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2021-3035 medium

📛 Threat Title

Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution

Category: vulnerability Published: Source updated: First seen: Last updated: Source: Paloalto Networks Security

Description

An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earli...

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

cve CVE-2021-3035

IOC database

Type
cve
Value
CVE-2021-3035
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

References (1)

  • Palo Alto Networks advisory: CVE-2021-3035 Paloalto Networks Security

    An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earli...

Remediations (8)

  • web:attack.mitre.org

    This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...

  • web:cybersecuritynews.com

    Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.

  • web:news.blizzard.com

    Patch 35.2 is rolling out with updates for the new season of Battlegrounds, new event cards, two Tavern Brawls, and more! Battlegrounds Updates Answer the call to defend Azeroth in Battlegrounds Season 13: CATACLYSM CALLS! Explore new and returning Trinkets, utilize two new keywords, try out two new heroes, and more.

  • web:nvd.nist.gov

    The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics. For ...

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

  • web:www.lansweeper.com

    Lansweeper's March Patch Tuesday audit highlights devices that lack the latest Microsoft updates. Scan your network now!

  • web:www.oracle.com

    Oracle Critical Patch Update Advisory - April 2025 Description A Critical Patch Update is a collection of patches for multiple security vulnerabilities. These patches address vulnerabilities in Oracle code and in third party components included in Oracle products. These patches are usually cumulative, but each advisory describes only the security patches added since the previous Critical Patch ...

  • web:zecurit.com

    Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.