.. / CVE-2020-7943

Exploit for Puppet Server/PuppetDB - Sensitive Information Disclosure (CVE-2020-7943)

Description:

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints, which may contain sensitive information when left exposed.

Nuclei Template

View the template here CVE-2020-7943.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2020/CVE-2020-7943.yaml
Copy

References:

https://puppet.com/security/cve/CVE-2020-7943
https://github.com/ARPSyndicate/cvemon
https://puppet.com/security/cve/CVE-2020-7943/
https://nvd.nist.gov/vuln/detail/CVE-2020-7943
https://tickets.puppetlabs.com/browse/PDB-4876