CVE-2025-46735

Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. This could lead to authenticated command injection in the underlyding powershell command prompt. Version 1.0.5 contains a fix for the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

07 May 2025, 14:13

Type Values Removed Values Added
Summary
  • (es) Terraform WinDNS Provider permite a los usuarios administrar los recursos de su servidor DNS de Windows a través de Terraform. Se detectó un problema de seguridad en e Terraform WinDNS Provider anterior a la versión 1.0.5. El recurso `windns_record` no depuraba las variables de entrada. Esto podría provocar la inyección de comandos autenticados en el símbolo del sistema de PowerShell subyacente. La versión 1.0.5 contiene una solución para este problema.

06 May 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-06 17:16

Updated : 2025-05-07 14:13


NVD link : CVE-2025-46735

Mitre link : CVE-2025-46735

CVE.ORG link : CVE-2025-46735


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')