FlawAtlas
Search the atlas
CVE-2025-46735 Low

Terraform WinDNS Provider improperly sanitizes input variables in `windns_record` in github.com/nrkno/terraform-provider-windns

Terraform WinDNS Provider improperly sanitizes input variables in `windns_record` in github.com/nrkno/terraform-provider-windns

Exploit probability 0.6%
Published May 15, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

8 explicit affected versions

Go github.com/nrkno/terraform-provider-windns
Go github.com/nrkno/terraform-provider-windns

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3670

Terraform WinDNS Provider improperly sanitizes input variables in `windns_record` in github.com/nrkno/terraform-provider-windns

View original source
Open Source Vulnerabilities GHSA-4vgf-2cm4-mp7c

## Impact: A security issue has been found in `terraform-provider-windns` before version `1.0.5`. The `windns_record` resource did not santize the input variables. This can lead to authenticated command injection in the underlyding powershell command prompt. ## Patches: [`83ef736 (fix: better input validation)`](https://github.com/nrkno/terraform-provider-windns/commit/c76f69610c1b502f90aaed8c4f102194530b5bce) ## Fixed versions: - `v1.0.5`

View original source
Open Source Vulnerabilities CVE-2025-46735

Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue has been found in Terraform WinDNS Provider before version `1.0.5`. The `windns_record` resource did not sanitize the input variables. This could lead to authenticated command injection in the underlyding powershell command prompt. Version 1.0.5 contains a fix for the issue.

View original source

05 / REFERENCES

Further evidence