Puppet (Perforce) operates a modestly represented but prominent infrastructure automation and configuration-management platform widely adopted in enterprise DevOps and continuous-delivery workflows, where its agent-based architecture and broad network exposure create a material attack surface. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, driven by weaknesses in input validation, certificate validation, and authentication mechanisms that recur across its core products including Puppet Enterprise, Puppet Agent, and Puppet Server. The exposure pattern reflects the sensitive nature of configuration-management software: flaws in these components can compromise infrastructure-wide credentials, secrets, and system state, making even moderately common weakness classes pose significant risk in operational environments. Defenders should treat Puppet advisories as high-priority for patching across deployed agents and servers, and should monitor for credential-exposure risks in particular; live severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Puppet (Perforce) over time
Of all the CVEs published by Puppet (Perforce) as a CNA, 60.4% affect products that Puppet (Perforce) develops as a vendor.
Of all the CVEs published that affect products developed by Puppet (Perforce), 42.6% are self-published by Puppet (Perforce) as a CNA.
Signals from CVEs in this vendor scope (130 CVEs).
130 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7529HIGH Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive inf | Jul 13, 2017 | 7.5 | 59 | NO | NO |
CVE-2016-2785CRITICAL Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restri | Jun 10, 2016 | 9.8 | 32 | NO | NO |
CVE-2022-3275CRITICAL Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsaniti | Oct 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-27023CRITICAL A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018 | Nov 18, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-7943HIGH Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server | Mar 11, 2020 | 7.5 | 31 | NO | YES |
CVE-2019-10694CRITICAL The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, | Dec 12, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-11747CRITICAL Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation o | Mar 21, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-11749CRITICAL When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, | Aug 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2022-0675CRITICAL In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unman | Mar 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2016-5713CRITICAL Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow u | Dec 6, 2017 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (130 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Puppet (Perforce).
Media articles that mention a CVE ID that affects a product developed by Puppet (Perforce) — matched by CVE ID, not by vendor name.