Puppet (Perforce)

First CVE: Feb 8, 2017Active for: 9 years
91
CVEs Published
More CVEs Published than 69% of tracked CNAs
9.1
Avg CVEs / Year
More Avg CVEs / Year than 50% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 65% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Puppet (Perforce) as a CNA, 60.4% affect products that Puppet (Perforce) develops as a vendor.

60.4%
39.6%
Self-reported: 55Third-party: 36

Of all the CVEs published that affect products developed by Puppet (Perforce), 42.6% are self-published by Puppet (Perforce) as a CNA.

42.6%
57.4%
Self-published: 55Published by other CNAs: 74

Trends Over Time

The number and severity of CVEs published by Puppet (Perforce) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2017
9 years ago
Most Recent CVE
Jul 16, 2026
8 days ago

Top CVEs

All CVEs published by Puppet (Perforce) as a CNA, regardless of affected vendor or product.

91 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentication requests. Parallel login
Jul 16, 20268.334NONO
Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.
May 15, 20268.733NONO
P4 Server versions prior to 2026.1 are configured with insecure default settings that, when exposed to untrusted networks, allow unauthenticated attackers to create arbitrary user
Apr 24, 20268.832NONO
Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing
Jul 3, 20266.731NONO
A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.
May 18, 20267.731NONO
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.
Nov 8, 20239.831NONO
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsaniti
Oct 7, 20229.831NONO
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018
Nov 18, 20219.831NONO
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server
Mar 11, 20207.531NOYES
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL,
Dec 12, 20199.831NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA91 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local13 (14.3%)
Network76 (83.5%)
Unknown0 (0.0%)
Physical1 (1.1%)
Adjacent Network1 (1.1%)
Attack Complexity
Low85 (93.4%)
High6 (6.6%)
Unknown0 (0.0%)
User Interaction
None78 (85.7%)
Unknown0 (0.0%)
Required9 (9.9%)
Privileges Required
Low38 (41.8%)
High9 (9.9%)
None44 (48.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (91 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.1% of CVEs· 80th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Puppet (Perforce) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Puppet (Perforce) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs