Vulnerability Details CVE-2020-7943
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Enterprise 2018.1.x stream prior to 2018.1.13 Puppet Enterprise prior to 2019.5.0 Puppet Server prior to 6.9.2 Puppet Server prior to 5.3.12 PuppetDB prior to 6.9.1 PuppetDB prior to 5.2.13 Resolved in: Puppet Enterprise 2018.1.13 Puppet Enterprise 2019.5.0 Puppet Server 6.9.2 Puppet Server 5.3.12 PuppetDB 6.9.1 PuppetDB 5.2.13
Exploit prediction scoring system (EPSS) score
EPSS Score 0.654
EPSS Ranking 98.4%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-7943
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.0
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.1
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.11
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.13
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.2
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.3
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.4
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.5
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.7
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.8
-
cpe:2.3:a:puppet:puppet_enterprise:2018.1.9
-
cpe:2.3:a:puppet:puppet_enterprise:2019.0
-
cpe:2.3:a:puppet:puppet_enterprise:2019.0.0
-
cpe:2.3:a:puppet:puppet_enterprise:2019.0.1
-
cpe:2.3:a:puppet:puppet_enterprise:2019.0.2
-
cpe:2.3:a:puppet:puppet_enterprise:2019.0.3
-
cpe:2.3:a:puppet:puppet_enterprise:2019.0.4
-
cpe:2.3:a:puppet:puppet_enterprise:2019.1.0
-
cpe:2.3:a:puppet:puppet_enterprise:2019.1.1
-
cpe:2.3:a:puppet:puppet_enterprise:2019.1.3
-
cpe:2.3:a:puppet:puppet_enterprise:2019.2.0
-
cpe:2.3:a:puppet:puppet_enterprise:2019.2.1
-
cpe:2.3:a:puppet:puppet_enterprise:2019.2.2
-
cpe:2.3:a:puppet:puppet_enterprise:2019.4.0
-
cpe:2.3:a:puppet:puppet_enterprise:2019.5.0
-
cpe:2.3:a:puppet:puppet_server:-
-
cpe:2.3:a:puppet:puppet_server:0.1.10
-
cpe:2.3:a:puppet:puppet_server:0.1.11
-
cpe:2.3:a:puppet:puppet_server:0.1.12
-
cpe:2.3:a:puppet:puppet_server:0.1.13
-
cpe:2.3:a:puppet:puppet_server:0.1.14
-
cpe:2.3:a:puppet:puppet_server:0.1.15
-
cpe:2.3:a:puppet:puppet_server:0.1.16
-
cpe:2.3:a:puppet:puppet_server:0.1.2
-
cpe:2.3:a:puppet:puppet_server:0.1.3
-
cpe:2.3:a:puppet:puppet_server:0.1.4
-
cpe:2.3:a:puppet:puppet_server:0.1.5
-
cpe:2.3:a:puppet:puppet_server:0.1.6
-
cpe:2.3:a:puppet:puppet_server:0.1.7
-
cpe:2.3:a:puppet:puppet_server:0.1.8
-
cpe:2.3:a:puppet:puppet_server:0.1.9
-
cpe:2.3:a:puppet:puppet_server:0.2.0
-
cpe:2.3:a:puppet:puppet_server:0.2.1
-
cpe:2.3:a:puppet:puppet_server:0.2.2
-
cpe:2.3:a:puppet:puppet_server:0.3.0
-
cpe:2.3:a:puppet:puppet_server:0.4.0
-
cpe:2.3:a:puppet:puppet_server:0.4.1
-
cpe:2.3:a:puppet:puppet_server:1.0.0
-
cpe:2.3:a:puppet:puppet_server:1.0.1
-
cpe:2.3:a:puppet:puppet_server:1.0.2
-
cpe:2.3:a:puppet:puppet_server:1.0.3
-
cpe:2.3:a:puppet:puppet_server:1.0.8
-
cpe:2.3:a:puppet:puppet_server:1.1.0
-
cpe:2.3:a:puppet:puppet_server:1.1.1
-
cpe:2.3:a:puppet:puppet_server:1.1.2
-
cpe:2.3:a:puppet:puppet_server:1.1.3
-
cpe:2.3:a:puppet:puppet_server:1.2.0
-
cpe:2.3:a:puppet:puppet_server:2.0.0
-
cpe:2.3:a:puppet:puppet_server:2.1.0
-
cpe:2.3:a:puppet:puppet_server:2.1.1
-
cpe:2.3:a:puppet:puppet_server:2.1.2
-
cpe:2.3:a:puppet:puppet_server:2.1.3
-
cpe:2.3:a:puppet:puppet_server:2.2.0
-
cpe:2.3:a:puppet:puppet_server:2.2.1
-
cpe:2.3:a:puppet:puppet_server:2.3.0
-
cpe:2.3:a:puppet:puppet_server:2.3.1
-
cpe:2.3:a:puppet:puppet_server:2.3.2
-
cpe:2.3:a:puppet:puppet_server:2.4.0
-
cpe:2.3:a:puppet:puppet_server:2.5.0
-
cpe:2.3:a:puppet:puppet_server:2.6.0
-
cpe:2.3:a:puppet:puppet_server:2.6.1
-
cpe:2.3:a:puppet:puppet_server:2.7.0
-
cpe:2.3:a:puppet:puppet_server:2.7.1
-
cpe:2.3:a:puppet:puppet_server:2.7.2
-
cpe:2.3:a:puppet:puppet_server:2.8.0
-
cpe:2.3:a:puppet:puppet_server:2.8.1
-
cpe:2.3:a:puppet:puppet_server:5.0.0
-
cpe:2.3:a:puppet:puppet_server:5.1.0
-
cpe:2.3:a:puppet:puppet_server:5.1.1
-
cpe:2.3:a:puppet:puppet_server:5.1.2
-
cpe:2.3:a:puppet:puppet_server:5.1.3
-
cpe:2.3:a:puppet:puppet_server:5.1.4
-
cpe:2.3:a:puppet:puppet_server:5.1.5
-
cpe:2.3:a:puppet:puppet_server:5.1.6
-
cpe:2.3:a:puppet:puppet_server:5.2.0
-
cpe:2.3:a:puppet:puppet_server:5.3.0
-
cpe:2.3:a:puppet:puppet_server:5.3.1
-
cpe:2.3:a:puppet:puppet_server:5.3.10
-
cpe:2.3:a:puppet:puppet_server:5.3.11
-
cpe:2.3:a:puppet:puppet_server:5.3.12
-
cpe:2.3:a:puppet:puppet_server:5.3.2
-
cpe:2.3:a:puppet:puppet_server:5.3.3
-
cpe:2.3:a:puppet:puppet_server:5.3.4
-
cpe:2.3:a:puppet:puppet_server:5.3.5
-
cpe:2.3:a:puppet:puppet_server:5.3.6
-
cpe:2.3:a:puppet:puppet_server:5.3.7
-
cpe:2.3:a:puppet:puppet_server:5.3.8
-
cpe:2.3:a:puppet:puppet_server:5.3.9
-
cpe:2.3:a:puppet:puppet_server:6.0.0
-
cpe:2.3:a:puppet:puppet_server:6.0.1
-
cpe:2.3:a:puppet:puppet_server:6.0.2
-
cpe:2.3:a:puppet:puppet_server:6.0.3
-
cpe:2.3:a:puppet:puppet_server:6.0.4
-
cpe:2.3:a:puppet:puppet_server:6.0.5
-
cpe:2.3:a:puppet:puppet_server:6.1.0
-
cpe:2.3:a:puppet:puppet_server:6.2.0
-
cpe:2.3:a:puppet:puppet_server:6.2.1
-
cpe:2.3:a:puppet:puppet_server:6.3.0
-
cpe:2.3:a:puppet:puppet_server:6.3.1
-
cpe:2.3:a:puppet:puppet_server:6.3.2
-
cpe:2.3:a:puppet:puppet_server:6.3.3
-
cpe:2.3:a:puppet:puppet_server:6.4.0
-
cpe:2.3:a:puppet:puppet_server:6.5.0
-
cpe:2.3:a:puppet:puppet_server:6.6.0
-
cpe:2.3:a:puppet:puppet_server:6.7.0
-
cpe:2.3:a:puppet:puppet_server:6.7.1
-
cpe:2.3:a:puppet:puppet_server:6.7.2
-
cpe:2.3:a:puppet:puppet_server:6.8.0
-
cpe:2.3:a:puppet:puppet_server:6.9.0
-
cpe:2.3:a:puppet:puppet_server:6.9.1
-
cpe:2.3:a:puppet:puppetdb:0.10.0
-
cpe:2.3:a:puppet:puppetdb:0.11.0
-
cpe:2.3:a:puppet:puppetdb:0.9.0
-
cpe:2.3:a:puppet:puppetdb:0.9.1
-
cpe:2.3:a:puppet:puppetdb:0.9.2
-
cpe:2.3:a:puppet:puppetdb:1.0.0
-
cpe:2.3:a:puppet:puppetdb:1.0.1
-
cpe:2.3:a:puppet:puppetdb:1.0.2
-
cpe:2.3:a:puppet:puppetdb:1.0.3
-
cpe:2.3:a:puppet:puppetdb:1.0.4
-
cpe:2.3:a:puppet:puppetdb:1.0.5
-
cpe:2.3:a:puppet:puppetdb:1.1.0
-
cpe:2.3:a:puppet:puppetdb:1.1.1
-
cpe:2.3:a:puppet:puppetdb:1.2.0
-
cpe:2.3:a:puppet:puppetdb:1.3.0
-
cpe:2.3:a:puppet:puppetdb:1.3.1
-
cpe:2.3:a:puppet:puppetdb:1.3.2
-
cpe:2.3:a:puppet:puppetdb:1.3.3
-
cpe:2.3:a:puppet:puppetdb:1.4.0
-
cpe:2.3:a:puppet:puppetdb:1.5.0
-
cpe:2.3:a:puppet:puppetdb:1.5.1
-
cpe:2.3:a:puppet:puppetdb:1.5.2
-
cpe:2.3:a:puppet:puppetdb:1.6.0
-
cpe:2.3:a:puppet:puppetdb:1.6.1
-
cpe:2.3:a:puppet:puppetdb:1.6.2
-
cpe:2.3:a:puppet:puppetdb:1.6.3
-
cpe:2.3:a:puppet:puppetdb:2.0.0
-
cpe:2.3:a:puppet:puppetdb:2.1.0
-
cpe:2.3:a:puppet:puppetdb:2.2.0
-
cpe:2.3:a:puppet:puppetdb:2.2.1
-
cpe:2.3:a:puppet:puppetdb:2.2.2
-
cpe:2.3:a:puppet:puppetdb:2.3.0
-
cpe:2.3:a:puppet:puppetdb:2.3.1
-
cpe:2.3:a:puppet:puppetdb:2.3.2
-
cpe:2.3:a:puppet:puppetdb:2.3.3
-
cpe:2.3:a:puppet:puppetdb:2.3.4
-
cpe:2.3:a:puppet:puppetdb:2.3.5
-
cpe:2.3:a:puppet:puppetdb:2.3.6
-
cpe:2.3:a:puppet:puppetdb:2.3.7
-
cpe:2.3:a:puppet:puppetdb:2.3.8
-
cpe:2.3:a:puppet:puppetdb:3.0.0
-
cpe:2.3:a:puppet:puppetdb:3.0.1
-
cpe:2.3:a:puppet:puppetdb:3.0.2
-
cpe:2.3:a:puppet:puppetdb:3.1.0
-
cpe:2.3:a:puppet:puppetdb:3.1.1
-
cpe:2.3:a:puppet:puppetdb:3.2.0
-
cpe:2.3:a:puppet:puppetdb:3.2.1
-
cpe:2.3:a:puppet:puppetdb:3.2.2
-
cpe:2.3:a:puppet:puppetdb:3.2.3
-
cpe:2.3:a:puppet:puppetdb:3.2.4
-
cpe:2.3:a:puppet:puppetdb:4.0.0
-
cpe:2.3:a:puppet:puppetdb:4.0.1
-
cpe:2.3:a:puppet:puppetdb:4.0.2
-
cpe:2.3:a:puppet:puppetdb:4.1.0
-
cpe:2.3:a:puppet:puppetdb:4.1.1
-
cpe:2.3:a:puppet:puppetdb:4.1.2
-
cpe:2.3:a:puppet:puppetdb:4.1.3
-
cpe:2.3:a:puppet:puppetdb:4.1.4
-
cpe:2.3:a:puppet:puppetdb:4.2.0
-
cpe:2.3:a:puppet:puppetdb:4.2.1
-
cpe:2.3:a:puppet:puppetdb:4.2.2
-
cpe:2.3:a:puppet:puppetdb:4.2.3
-
cpe:2.3:a:puppet:puppetdb:4.2.3.1
-
cpe:2.3:a:puppet:puppetdb:4.2.3.2
-
cpe:2.3:a:puppet:puppetdb:4.2.3.5
-
cpe:2.3:a:puppet:puppetdb:4.2.3.6
-
cpe:2.3:a:puppet:puppetdb:4.2.3.7
-
cpe:2.3:a:puppet:puppetdb:4.2.3.8
-
cpe:2.3:a:puppet:puppetdb:4.2.4
-
cpe:2.3:a:puppet:puppetdb:4.2.5
-
cpe:2.3:a:puppet:puppetdb:4.3.0
-
cpe:2.3:a:puppet:puppetdb:4.3.1
-
cpe:2.3:a:puppet:puppetdb:4.3.2
-
cpe:2.3:a:puppet:puppetdb:4.4.0
-
cpe:2.3:a:puppet:puppetdb:4.4.1
-
cpe:2.3:a:puppet:puppetdb:4.4.2
-
cpe:2.3:a:puppet:puppetdb:5.0.0
-
cpe:2.3:a:puppet:puppetdb:5.0.1
-
cpe:2.3:a:puppet:puppetdb:5.1.0
-
cpe:2.3:a:puppet:puppetdb:5.1.1
-
cpe:2.3:a:puppet:puppetdb:5.1.2
-
cpe:2.3:a:puppet:puppetdb:5.1.3
-
cpe:2.3:a:puppet:puppetdb:5.1.4
-
cpe:2.3:a:puppet:puppetdb:5.1.5
-
cpe:2.3:a:puppet:puppetdb:5.1.6
-
cpe:2.3:a:puppet:puppetdb:5.2.0
-
cpe:2.3:a:puppet:puppetdb:5.2.1
-
cpe:2.3:a:puppet:puppetdb:5.2.10
-
cpe:2.3:a:puppet:puppetdb:5.2.11
-
cpe:2.3:a:puppet:puppetdb:5.2.12
-
cpe:2.3:a:puppet:puppetdb:5.2.13
-
cpe:2.3:a:puppet:puppetdb:5.2.2
-
cpe:2.3:a:puppet:puppetdb:5.2.3
-
cpe:2.3:a:puppet:puppetdb:5.2.4
-
cpe:2.3:a:puppet:puppetdb:5.2.5
-
cpe:2.3:a:puppet:puppetdb:5.2.6
-
cpe:2.3:a:puppet:puppetdb:5.2.7
-
cpe:2.3:a:puppet:puppetdb:5.2.8
-
cpe:2.3:a:puppet:puppetdb:5.2.9
-
cpe:2.3:a:puppet:puppetdb:6.0.0
-
cpe:2.3:a:puppet:puppetdb:6.0.1
-
cpe:2.3:a:puppet:puppetdb:6.0.2
-
cpe:2.3:a:puppet:puppetdb:6.0.3
-
cpe:2.3:a:puppet:puppetdb:6.0.4
-
cpe:2.3:a:puppet:puppetdb:6.1.0
-
cpe:2.3:a:puppet:puppetdb:6.10.0
-
cpe:2.3:a:puppet:puppetdb:6.2.0
-
cpe:2.3:a:puppet:puppetdb:6.3.0
-
cpe:2.3:a:puppet:puppetdb:6.3.1
-
cpe:2.3:a:puppet:puppetdb:6.3.2
-
cpe:2.3:a:puppet:puppetdb:6.3.3
-
cpe:2.3:a:puppet:puppetdb:6.3.4
-
cpe:2.3:a:puppet:puppetdb:6.3.5
-
cpe:2.3:a:puppet:puppetdb:6.3.6
-
cpe:2.3:a:puppet:puppetdb:6.3.7
-
cpe:2.3:a:puppet:puppetdb:6.4.0
-
cpe:2.3:a:puppet:puppetdb:6.5.0
-
cpe:2.3:a:puppet:puppetdb:6.6.0
-
cpe:2.3:a:puppet:puppetdb:6.7.0
-
cpe:2.3:a:puppet:puppetdb:6.7.1
-
cpe:2.3:a:puppet:puppetdb:6.7.2
-
cpe:2.3:a:puppet:puppetdb:6.7.3
-
cpe:2.3:a:puppet:puppetdb:6.8.0
-
cpe:2.3:a:puppet:puppetdb:6.8.1
-
cpe:2.3:a:puppet:puppetdb:6.9.0
-
cpe:2.3:a:puppet:puppetdb:6.9.1