CVE-2025-46735

Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. This could lead to authenticated command injection in the underlyding powershell command prompt. Version 1.0.5 contains a fix for the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

07 May 2025, 14:13

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-06 17:16

Updated : 2025-05-07 14:13


NVD link : CVE-2025-46735

Mitre link : CVE-2025-46735

CVE.ORG link : CVE-2025-46735


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')