CVE-2021-3040
medium
📛 Threat Title
Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution
Description
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earli...
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
cve
CVE-2021-3040
IOC database
- Type
- cve
- Value
CVE-2021-3040- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Bridgecrew Checkov: Unsafe deserialization of Terraform files allows code execution
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
Palo Alto Networks advisory: CVE-2021-3040
Paloalto Networks Security
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earli...
Remediations (8)
-
web:adaptiva.com
Identify threats with Tenable and fix vulnerabilities quickly with OneSite Patch . Prioritize deployments based on Tenable's Vulnerability Priority Rating (VPR) to ensure rapid remediation as soon as a patch is available. IT and security teams can precisely mirror their desired patching strategies once, then automation takes care of the rest.
-
web:attack.mitre.org
This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...
-
web:docs.tenable.com
Verifying Patches The information that Tenable plugins provide to enumerate software versions can be used to verify that authorized software is updated with the latest patches. The Patch Report (66334) Plugin summarizes a list of patches that need to be installed and enabled on an asset. Use this plugin to track how often a patch assessment is made over time or to extract the data to perform ...
-
web:nvd.nist.gov
Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...
-
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
-
web:translate.google.com
Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.
-
web:www.cyera.com
Cyera Research identifies CVE -2026-34040, a critical Docker bypass. Learn how 1MB+ requests silence security plugins and how to patch Docker Engine 29.3.1 today.
-
web:www.ign.com
The v40.20 Patch for Fortnite has arrived, bringing with it Save the World F2P, Showdown Act II, and various fixes and
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.