Puppet

Vendor:

First CVE: Mar 3, 2010 · Active for 16 years

49
Total CVEs
More Total CVEs than 96% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 93% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Puppet over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 3, 2010
16 years ago
Most Recent CVE
Sep 24, 2025
303 days ago

CVE Severity & Scoring

Puppet49 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local4 (8.2%)
Network10 (20.4%)
Unknown35 (71.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (26.5%)
High1 (2.0%)
Unknown35 (71.4%)
User Interaction
None12 (24.5%)
Unknown35 (71.4%)
Required2 (4.1%)
Privileges Required
Low8 (16.3%)
High3 (6.1%)
None3 (6.1%)
Unknown35 (71.4%)

Top CVEs

Signals from CVEs in this product scope (49 CVEs).

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Puppet Server before 2.3.2 and Ruby puppetmaster in Puppet 4.x before 4.4.2 and in Puppet Agent before 1.4.2 might allow remote attackers to bypass intended auth.conf access restri
Jun 10, 20169.832NONO
A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.
Jul 20, 20218.828NONO
Versions of Puppet prior to 4.10.1 will deserialize data off the wire (from the agent to the server, in this case) with a attacker-specified format. This could be used to force YAM
Jul 5, 20178.227NONO
Puppet Enterprise 2016.4.x prior to 2016.4.12, Puppet Enterprise 2017.3.x prior to 2017.3.7, Puppet Enterprise 2018.1.x prior to 2018.1.1, Puppet Agent 1.10.x prior to 1.10.13, Pup
Jun 11, 20188.826NONO
The pe_mcollective module in Puppet Enterprise (PE) before 2.7.1 does not properly restrict access to a catalog of private SSL keys, which allows remote authenticated users to obta
Mar 14, 20148.526NONO
Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, and Puppet Agent 5.5.x prior to 5.5.2 on Windows only, with a specially crafted configuration file an attac
Jun 11, 20187.824NONO
In Puppet Agent 1.10.x prior to 1.10.13, Puppet Agent 5.3.x prior to 5.3.7, Puppet Agent 5.5.x prior to 5.5.2, Facter on Windows is vulnerable to a DLL preloading attack, which cou
Jun 11, 20187.824NONO
The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and
Mar 20, 20139.024NONO
In Puppet Enterprise versions 2025.4.0 and 2025.5, the encryption key used for encrypting content in the Infra Assistant database was not excluded from the files gathered by Puppet
Sep 24, 20256.923NONO
A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
Nov 18, 20216.523NONO

Exploit Exposure

Signals from CVEs in this product scope (49 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (49 CVEs).

Media Mentions

Signals from CVEs in this product scope (49 CVEs).

Top CNAs Publishing CVEs For Puppet

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.4.119.82.9%00
4.4.019.82.9%00
4.3.219.82.9%00
4.3.119.82.9%00
4.3.019.82.9%00
4.2.319.82.9%00
4.2.219.82.9%00
4.2.119.82.9%00
4.2.019.82.9%00
4.1.019.82.9%00
4.0.019.82.9%00
3.2.324.31.0%00
3.2.224.31.0%00
3.2.135.41.8%00
3.2.035.41.8%00
3.1.019.04.9%00
2.7.9154.41.8%00
2.7.8154.41.8%00
2.7.7124.82.1%00
2.7.6154.41.8%00