← Vulnerability feed

Vulnerability record · CVE-2020-7943 · published 11 March 2020

CVE-2020-7943: Puppet enterprise incorrect default permissions vulnerability

Puppet · Puppet Enterprise

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Enterprise 2018.1.x stream prior to 2018.1.13 Puppet Enterprise prior to 2019.5.0 Puppet Server prior to 6.9.2 Puppet Server prior to 5.3.12 PuppetDB prior to 6.9.1 PuppetDB prior to 5.2.13 Resolved in: Puppet Enterprise 2018.1.13 Puppet Enterprise 2019.5.0 Puppet Server 6.9.2 Puppet Server 5.3.12 PuppetDB 6.9.1 PuppetDB 5.2.13

7.5 CVSS 3.1 High EPSS 7.9% · top 5.5% CWE-276 · Incorrect default permissions
7.5CVSS 3.1 base score, v2 5.0
7.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Enterprise 2018.1.x stream prior to 2018.1.13 Puppet Enterprise prior to 2019.5.0 Puppet Server prior to 6.9.2 Puppet Server prior to 5.3.12 PuppetDB prior to 6.9.1 PuppetDB prior to 5.2.13 Resolved in: Puppet Enterprise 2018.1.13 Puppet Enterprise 2019.5.0 Puppet Server 6.9.2 Puppet Server 5.3.12 PuppetDB 6.9.1 PuppetDB 5.2.13

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7943 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5309Puppet enterprise vulnerabilityVersions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken session management for SAML implementations.EPSS 0.50%9.8CVE-2023-2530Puppet enterprise vulnerabilityA privilege escalation allowing remote code execution was discovered in the orchestration service.EPSS 1.1%9.8CVE-2021-27023Puppet agent vulnerabilityA flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different ho…EPSS 1.4%9.8CVE-2019-10694Puppet enterprise hard-coded credentials vulnerabilityThe express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin passwor…EPSS 1.1%9.8CVE-2018-11749Puppet enterprise cleartext transmission vulnerabilityWhen users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affec…EPSS 0.76%9.8CVE-2018-6512Puppet pe-razor-server code injection vulnerabilityThe previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet …EPSS 1.9%9.8CVE-2016-2788Puppet marionette collective improper access control vulnerabilityMCollective 2.7.0 and 2.8.x before 2.8.9, as used in Puppet Enterprise, allows remote attackers to execute arbitrary code via vectors related to the …EPSS 2.3%9.8CVE-2016-2786Puppet agent improper input validation vulnerabilityThe pxp-agent component in Puppet Enterprise 2015.3.x before 2015.3.3 and Puppet Agent 1.3.x before 1.3.6 does not properly validate server certifica…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2020-7943), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.