Puppetlabs maintains a focused portfolio of infrastructure-automation and configuration-management platforms, notably Puppet and Puppet Enterprise, that occupy a prominent role in enterprise deployment and lifecycle tooling despite a narrow product line. The vendor's vulnerability exposure reflects the authentication, input handling, and file-access control demands inherent to agent-based systems that operate with elevated privileges across managed infrastructure, with recurring weakness classes including improper input validation, link-following flaws, and authentication gaps. The recurring products—Puppet, Facter, and MCollective—form an integrated orchestration stack where a single vulnerability can span multiple components or affect the trust relationships between agents and management servers. Defenders should track this vendor's releases as part of infrastructure-management inventory, treating Puppet deployments as a security perimeter and prioritizing authentication and input-validation patches; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Puppetlabs over time
Signals from CVEs in this vendor scope (130 CVEs).
130 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7529HIGH Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive inf | Jul 13, 2017 | 7.5 | 59 | NO | NO |
CVE-2016-2785CRITICAL Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restri | Jun 10, 2016 | 9.8 | 32 | NO | NO |
CVE-2022-3275CRITICAL Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsaniti | Oct 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-27023CRITICAL A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018 | Nov 18, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-7943HIGH Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server | Mar 11, 2020 | 7.5 | 31 | NO | YES |
CVE-2019-10694CRITICAL The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL, | Dec 12, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-11747CRITICAL Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation o | Mar 21, 2019 | 9.8 | 31 | NO | NO |
CVE-2018-11749CRITICAL When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3, | Aug 24, 2018 | 9.8 | 31 | NO | NO |
CVE-2022-0675CRITICAL In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unman | Mar 2, 2022 | 9.8 | 30 | NO | NO |
CVE-2016-5713CRITICAL Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow u | Dec 6, 2017 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (130 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Puppetlabs.
Media articles that mention a CVE ID that affects a product developed by Puppetlabs — matched by CVE ID, not by vendor name.