S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2020-7943 Scanner

CVE-2020-7943 scanner - Information Disclosure vulnerability in Puppet Enterprise 2018.1.x stream, Puppet Enterprise, Puppet Server, PuppetDB

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.1k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-7943
7.5
CVSS

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Enterprise 2018.1.x stream prior to 2018.1.13 Puppet Enterprise prior to 2019.5.0 Puppet Server prior to 6.9.2 Puppet Server prior to 5.3.12 PuppetDB prior to 6.9.1 PuppetDB prior to 5.2.13 Resolved in: Puppet Enterprise 2018.1.13 Puppet Enterprise 2019.5.0 Puppet Server 6.9.2 Puppet Server 5.3.12 PuppetDB 6.9.1 PuppetDB 5.2.13

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Puppet Enterprise 2018.1.x streamby n/a
prior to 2018.1.13
Puppet Enterpriseby n/a
prior to 2019.5.0
Puppet Serverby n/a
prior to 6.9.2
PuppetDBby n/a
prior to 6.9.1
Updated Aug 21, 2026View on NVD →
Detail

Puppet Enterprise 2018.1.x stream, Puppet Enterprise, Puppet Server, and PuppetDB are IT automation software that helps organizations manage their infrastructure. Puppet Enterprise streamlines the process of deploying, managing, and securing IT infrastructure. Puppet Server is a server that manages Puppet agents, while PuppetDB is a database that stores Puppet infrastructure data. Together, they provide organizations with useful performance and debugging information via their metrics API endpoints.

The CVE-2020-7943 vulnerability was detected in the aforementioned products. This vulnerability allowed sensitive information to be exposed via the metrics API endpoints. Previously, these endpoints were open to the local network, leaving the infrastructure susceptible to attacks.

When exploited, this vulnerability can lead to sensitive information exposure, including hostnames, resource names, titles, function names, and class names. Cybercriminals can use this information to gain unauthorized access, steal data, and launch further attacks against the organization. It is a high-risk vulnerability that can cause tremendous damage if left unaddressed.

By using the pro features of the s4e.io platform, organizations can easily and quickly learn about vulnerabilities in their digital assets. The platform provides a comprehensive vulnerability assessment of an organization's IT infrastructure, identifies areas of risk, and provides actionable recommendations to mitigate those risks. With its user-friendly interface, organizations can manage their cybersecurity posture effectively. Protecting an organization's infrastructure from vulnerabilities is essential, and with the help of s4e.io, it can be done with ease.

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations can take the following precautions:

  • Apply all available security patches and updates provided by Puppet Labs.
  • Limit access to the metrics API endpoints to trusted IPs only.
  • Use a VPN to connect to the management network.
  • Monitor network traffic for unusual behavior.
  • Deploy intrusion detection systems to detect and prevent attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.