Puppet
Vendor:
First CVE: Mar 3, 2010 · Active for 16 years
49
Total CVEs
More Total CVEs than 96% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Puppet over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2010
16 years ago
Most Recent CVE
Sep 24, 2025
303 days ago
CVE Severity & Scoring
Puppet49 CVEs
22%
55%
20%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (8.2%)
Network10 (20.4%)
Unknown35 (71.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (26.5%)
High1 (2.0%)
Unknown35 (71.4%)
User Interaction
None12 (24.5%)
Unknown35 (71.4%)
Required2 (4.1%)
Privileges Required
Low8 (16.3%)
High3 (6.1%)
None3 (6.1%)
Unknown35 (71.4%)
Top CVEs
Signals from CVEs in this product scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2785CRITICAL Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restri | Jun 10, 2016 | 9.8 | 32 | NO | NO |
CVE-2021-27021HIGH A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query. | Jul 20, 2021 | 8.8 | 28 | NO | NO |
CVE-2017-2295HIGH Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAM | Jul 5, 2017 | 8.2 | 27 | NO | NO |
CVE-2018-6513HIGH Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Pup | Jun 11, 2018 | 8.8 | 26 | NO | NO |
CVE-2013-1398HIGH The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obta | Mar 14, 2014 | 8.5 | 26 | NO | NO |
CVE-2018-6515HIGH Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attac | Jun 11, 2018 | 7.8 | 24 | NO | NO |
CVE-2018-6514HIGH In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which cou | Jun 11, 2018 | 7.8 | 24 | NO | NO |
CVE-2013-1640HIGH The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and | Mar 20, 2013 | 9.0 | 24 | NO | NO |
CVE-2025-10360MEDIUM In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet | Sep 24, 2025 | 6.9 | 23 | NO | NO |
CVE-2021-27025MEDIUM A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'. | Nov 18, 2021 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (49 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (49 CVEs).
Media Mentions
Signals from CVEs in this product scope (49 CVEs).
Top CNAs Publishing CVEs For Puppet
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.4.1 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.4.0 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.3.2 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.3.1 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.3.0 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.2.3 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.2.2 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.2.1 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.2.0 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.1.0 | 1 | 9.8 | 2.9% | 0 | 0 |
| 4.0.0 | 1 | 9.8 | 2.9% | 0 | 0 |
| 3.2.3 | 2 | 4.3 | 1.0% | 0 | 0 |
| 3.2.2 | 2 | 4.3 | 1.0% | 0 | 0 |
| 3.2.1 | 3 | 5.4 | 1.8% | 0 | 0 |
| 3.2.0 | 3 | 5.4 | 1.8% | 0 | 0 |
| 3.1.0 | 1 | 9.0 | 4.9% | 0 | 0 |
| 2.7.9 | 15 | 4.4 | 1.8% | 0 | 0 |
| 2.7.8 | 15 | 4.4 | 1.8% | 0 | 0 |
| 2.7.7 | 12 | 4.8 | 2.1% | 0 | 0 |
| 2.7.6 | 15 | 4.4 | 1.8% | 0 | 0 |