Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Puppetlabs

First CVE: Mar 3, 2010Active for: 16 yearsTotal CVEs: 163
15.0
VTI Score
Low

Puppetlabs maintains a focused portfolio of infrastructure-automation and configuration-management platforms, notably Puppet and Puppet Enterprise, that occupy a prominent role in enterprise deployment and lifecycle tooling despite a narrow product line. The vendor's vulnerability exposure reflects the authentication, input handling, and file-access control demands inherent to agent-based systems that operate with elevated privileges across managed infrastructure, with recurring weakness classes including improper input validation, link-following flaws, and authentication gaps. The recurring products—Puppet, Facter, and MCollective—form an integrated orchestration stack where a single vulnerability can span multiple components or affect the trust relationships between agents and management servers. Defenders should track this vendor's releases as part of infrastructure-management inventory, treating Puppet deployments as a security perimeter and prioritizing authentication and input-validation patches; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
130
Total CVEs
More Total CVEs than 98% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Puppetlabs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2010
16 years ago
Most Recent CVE
Sep 24, 2025
304 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (130 CVEs).

130 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-7529HIGH
Nginx versions since 0.5.6 up to and including 1.13.2 are vulnerable to integer overflow vulnerability in nginx range filter module resulting into leak of potentially sensitive inf
Jul 13, 20177.559NONO
CVE-2016-2785CRITICAL
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restri
Jun 10, 20169.832NONO
CVE-2022-3275CRITICAL
Command injection is possible in the puppetlabs-apt module prior to version 9.0.0. A malicious actor is able to exploit this vulnerability only if they are able to provide unsaniti
Oct 7, 20229.831NONO
CVE-2021-27023CRITICAL
A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018
Nov 18, 20219.831NONO
CVE-2020-7943HIGH
Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server
Mar 11, 20207.531NOYES
CVE-2019-10694CRITICAL
The express install, which is the suggested way to install Puppet Enterprise, gives the user a URL at the end of the install to set the admin password. If they do not use that URL,
Dec 12, 20199.831NONO
CVE-2018-11747CRITICAL
Previously, Puppet Discovery was shipped with a default generated TLS certificate in the nginx container. In version 1.4.0, a unique certificate will be generated on installation o
Mar 21, 20199.831NONO
CVE-2018-11749CRITICAL
When users are configured to use startTLS with RBAC LDAP, at login time, the user's credentials are sent via plaintext to the LDAP server. This affects Puppet Enterprise 2018.1.3,
Aug 24, 20189.831NONO
CVE-2022-0675CRITICAL
In certain situations it is possible for an unmanaged rule to exist on the target system that has the same comment as the rule specified in the manifest. This could allow for unman
Mar 2, 20229.830NONO
CVE-2016-5713CRITICAL
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow u
Dec 6, 20179.830NONO
View all 130 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products130 CVEs
11%
52%
24%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local9 (6.9%)
Network65 (50.0%)
Unknown55 (42.3%)
Physical0 (0.0%)
Adjacent Network1 (0.8%)
Attack Complexity
Low69 (53.1%)
High6 (4.6%)
Unknown55 (42.3%)
User Interaction
None61 (46.9%)
Unknown55 (42.3%)
Required14 (10.8%)
Privileges Required
Low28 (21.5%)
High7 (5.4%)
None40 (30.8%)
Unknown55 (42.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (130 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
0.8% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Puppetlabs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Puppetlabs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Puppetlabs's Products

View all 3 CNAs →

Top CWEs