Description
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints, which may contain sensitive information when left exposed.
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints, which may contain sensitive information when left exposed.
id: CVE-2020-7943
info:
name: Puppet Server/PuppetDB - Sensitive Information Disclosure
author: c-sh0
severity: high
description: Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints, which may contain sensitive information when left exposed.
impact: |
An attacker can exploit this vulnerability to gain access to sensitive information stored in Puppet Server/PuppetDB.
remediation: |
Apply the necessary patches or updates provided by Puppet to fix the vulnerability and ensure sensitive information is properly protected.
reference:
- https://puppet.com/security/cve/CVE-2020-7943
- https://tickets.puppetlabs.com/browse/PDB-4876
- https://puppet.com/security/cve/CVE-2020-7943/
- https://nvd.nist.gov/vuln/detail/CVE-2020-7943
- https://github.com/ARPSyndicate/cvemon
classification:
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cve-id: CVE-2020-7943
cwe-id: CWE-276,NVD-CWE-noinfo
epss-score: 0.07884
epss-percentile: 0.94409
cpe: cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: puppet
product: puppet_enterprise
tags: cve2020,cve,puppet,exposure,puppetdb,vuln
http:
- method: GET
path:
- "{{BaseURL}}/metrics/v1/mbeans"
matchers-condition: and
matchers:
- type: word
part: body
words:
- "trapperkeeper"
- type: word
part: header
words:
- "application/json"
- type: status
status:
- 200
# digest: 4a0a004730450221009f88d8e4661ad8903716c90b16da052ed4e7f95e57bef5625517265947cad3d40220545f34ffc8fb3a7f5c3fc0c4cb9aa9dca701854fdbf3c15562cf11e7b3bde7d9:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.