checkov is vulnerable to Unsafe Deserialization
90
Critical Risk
An unsafe deserialization vulnerability in checkov allows an attacker to execute arbitrary code when scanning a malformed Terraform file. This could allow an attacker to achieve elevated privileges where checkov is running, e.g. in the CI/CD pipeline or a developer's machine, allowing an attacker to potentially exfiltrate secrets of the environment.
You are affected if you are using a version that falls within the vulnerable range.
checkov is vulnerable to Unsafe Deserialization in versions 0.0.0 - 3.2.414.
Upgrade checkov to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant