CVE-2020-7943
Linux Debian vulnerability analysis and mitigation

Overview

Puppet Server and PuppetDB were found to contain a vulnerability where their metrics API endpoints leaked sensitive information to the local network. The vulnerability (CVE-2020-7943) was discovered and disclosed in March 2020, affecting Puppet Enterprise, Puppet Server, and PuppetDB systems. The initial fix was found to be incomplete, leading to a complete resolution in subsequent versions (Puppet Security).

Technical details

The vulnerability existed in the metrics API endpoints of both Puppet Server and PuppetDB. For PuppetDB, the exposed information included hostnames, while Puppet Server exposed resource names, titles for defined types, function names, and class names. The vulnerability received a CVSS 3 Base Score of 7.5, indicating a high severity level. The issue specifically involved the trapperkeeper-metrics /v1 metrics API being openly accessible to the local network (Puppet Security).

Impact

The vulnerability could lead to the exposure of sensitive information through the metrics API endpoints. This included potential access to hostnames in PuppetDB and sensitive information contained within resource names, titles for defined types, function names, and class names in Puppet Server (Puppet Security).

Mitigation and workarounds

The vulnerability was initially addressed by disabling the trapperkeeper-metrics /v1 metrics API and restricting /v2 access to localhost by default. After discovering the initial fix was incomplete, complete resolution was achieved in Puppet Enterprise versions 2018.1.15 and 2019.7.0, Puppet Server versions 6.11.1 and 5.3.13, and PuppetDB versions 6.10.1 and 5.2.15 (Puppet Security).

Additional resources


SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22857MEDIUM6.8
  • Linux DebianLinux Debian
  • libwinpr
NoNoJan 14, 2026
CVE-2026-22856MEDIUM6.8
  • Linux DebianLinux Debian
  • freerdp3
NoNoJan 14, 2026
CVE-2026-22859MEDIUM5.6
  • Linux DebianLinux Debian
  • freerdp2
NoNoJan 14, 2026
CVE-2026-22858MEDIUM5.6
  • Linux DebianLinux Debian
  • freerdp-plugins
NoNoJan 14, 2026
CVE-2026-22036LOW3.7
  • JavaScriptJavaScript
  • node-undici
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management