Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2020-7943

Quick assessment

Affected
n/a Puppet Enterprise 2018.1.x stream
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Puppet和Puppet Server都是美国Puppet(Puppet)实验室的产品。Puppet是一套基于客户端/服务器(C/S)架构的配置管理工具,它可用于管理配置文件、用户、cron任务、软件包、系统服务等。Puppet Enterprise是Puppet的企业版。PuppetDB是Puppet的下一代开源存储服务,它可用于管理所有平台生成的数据存储和检索。Puppet Server是一款用于将配置从主服务器推送到其他服务器的软件。 Puppet Enterprise、Puppet Server

AI Predicted 5.3 Difficulty: Moderate EPSS 8.81% · P95

Public Exploits 1

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2020-7943

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Enterprise 2018.1.x stream prior to 2018.1.13 Puppet Enterprise prior to 2019.5.0 Puppet Server prior to 6.9.2 Puppet Server prior to 5.3.12 PuppetDB prior to 6.9.1 PuppetDB prior to 5.2.13 Resolved in: Puppet Enterprise 2018.1.13 Puppet Enterprise 2019.5.0 Puppet Server 6.9.2 Puppet Server 5.3.12 PuppetDB 6.9.1 PuppetDB 5.2.13
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
缺省权限不正确
Source: CVE Program / CVE List V5
Vulnerability Title
Puppet和PuppetDB 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Puppet和Puppet Server都是美国Puppet(Puppet)实验室的产品。Puppet是一套基于客户端/服务器(C/S)架构的配置管理工具,它可用于管理配置文件、用户、cron任务、软件包、系统服务等。Puppet Enterprise是Puppet的企业版。PuppetDB是Puppet的下一代开源存储服务,它可用于管理所有平台生成的数据存储和检索。Puppet Server是一款用于将配置从主服务器推送到其他服务器的软件。 Puppet Enterprise、Puppet Server
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
- Puppet Enterprise 2018.1.x stream prior to 2018.1.13 -
- Puppet Enterprise prior to 2019.5.0 -
- Puppet Server prior to 6.9.2 -
- PuppetDB prior to 6.9.1 -
- Resolved in Puppet Enterprise, Puppet Server, PuppetDB Puppet Enterprise 2018.1.13 and 2019.5.0 -

II. Public POCs for CVE-2020-7943

# POC Description Source Link Shenlong Link
1 Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints, which may contain sensitive information when left exposed. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-7943.yaml POC Details
2 PuppetDB dashboard and API endpoints were found accessible without authentication. PuppetDB stores infrastructure configuration data including node facts, catalogs, and reports. Unauthenticated access exposes sensitive infrastructure details such as hostnames, IP addresses, OS versions, installed packages, Puppet classes, and configuration parameters across the entire managed environment. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/misconfiguration/puppetdb-dashboard-unauth.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-7943

请登录查看更多情报信息。

Other References for CVE-2020-7943 (1)

Same Patch Batch · n/a · 2020-03-11 · 21 CVEs total

CVE-2019-9099 多款Moxa产品缓冲区错误漏洞
CVE-2020-10385 WordPress WPForms Contact Form插件跨站脚本漏洞
CVE-2019-16107 phpBB 跨站请求伪造漏洞
CVE-2019-19381 Abacus OAuth Login 跨站脚本漏洞
CVE-2020-5203 Fat-Free Framework 注入漏洞
CVE-2020-10376 Technicolor TC7337NET 安全漏洞
CVE-2019-9104 多款Moxa产品安全漏洞
CVE-2019-9103 多款Moxa产品信息泄露漏洞
CVE-2019-9102 多款Moxa产品跨站请求伪造漏洞
CVE-2019-9101 多款Moxa产品安全漏洞
CVE-2019-10808 utilitify 输入验证错误漏洞
CVE-2019-9098 多款Moxa产品输入验证错误漏洞
CVE-2019-9097 多款Moxa产品安全漏洞
CVE-2019-9096 多款Moxa产品安全漏洞
CVE-2019-9095 多款Moxa产品安全漏洞
CVE-2020-10181 Sumavision Enhanced Multimedia Router 跨站请求伪造漏洞
CVE-2020-8540 ZOHO ManageEngine Desktop Central 代码问题漏洞
CVE-2013-1753 Python xmlrpc客户端库资源管理错误漏洞
CVE-2016-1000111 Twisted 安全漏洞
CVE-2020-7598 minimist 输入验证错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2020-7943

No comments yet


Leave a comment