Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Polo-Sec

#53609of 53,625
1.1Total CVSS
Vulnerabilities · 1
PT-2025-19981
1.1
2025-05-06
Hashicorp · Terraform Windns Provider · CVE-2025-46735
**Name of the Vulnerable Software and Affected Versions** Terraform WinDNS Provider versions prior to 1.0.5 **Description** A security issue has been found in the Terraform WinDNS Provider, where the `windns record` resource did not sanitize the input variables, leading to authenticated command injection in the underlying PowerShell command prompt. **Recommendations** For versions prior to 1.0.5, update to version 1.0.5 to resolve the issue. As a temporary workaround, consider sanitizing the input variables for the `windns record` resource to prevent command injection.