id: CVE-2020-7943 info: name: Puppet Server/PuppetDB - Sensitive Information Disclosure author: c-sh0 severity: high description: Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints, which may contain sensitive information when left exposed. remediation: | Apply the necessary patches or updates provided by Puppet to fix the vulnerability and ensure sensitive information is properly protected. reference: - https://puppet.com/security/cve/CVE-2020-7943 - https://tickets.puppetlabs.com/browse/PDB-4876 - https://puppet.com/security/cve/CVE-2020-7943/ - https://nvd.nist.gov/vuln/detail/CVE-2020-7943 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 7.5 cve-id: CVE-2020-7943 cwe-id: CWE-276,NVD-CWE-noinfo epss-score: 0.08018 epss-percentile: 0.93582 cpe: cpe:2.3:a:puppet:puppet_enterprise:*:*:*:*:*:*:*:* metadata: max-request: 1 vendor: puppet product: puppet_enterprise tags: cve,cve2020,puppet,exposure,puppetdb http: - method: GET path: - "{{BaseURL}}/metrics/v1/mbeans" matchers-condition: and matchers: - type: word part: body words: - "trapperkeeper" - type: word part: header words: - "application/json" - type: status status: - 200 # digest: 4a0a00473045022100febd4d63ed2acc605cd7fa6525891c704aa8ade44f4c3d5933f67eaeaf51de49022047a024a3cd5a843a11af6ea3efb5d55f085e66415ea05c0cc8a8bcf436db730a:922c64590222798bb761d5b6d8e72950