CVEs we hold for Puppet
Records whose assigning authority named Puppet as the affected vendor. Newest identifiers first, capped at 200.
CVE-2024-9160Security Misconfiguration in Forge module PEADMPuppet PEADM Forge Module CVE-2023-5309Broken Session Management in Puppet EnterprisePuppet Enterprise CVE-2023-5255Denial of Service for Revocation of Auto Renewed CertificatesPuppet Enterprise CVE-2023-5214CVE-2023-5214 - Privilege Escalation in Puppet BoltPuppet Bolt CVE-2022-3276Puppetlabs-mysql Command InjectionPuppet puppetlabs-mysql CVE-2022-3275Puppetlabs-apt Command InjectionPuppet puppetlabs-apt CVE-2022-2394Sensitive Parameter Exposure in Puppet Bolt prior to 3.24Puppet Bolt CVE-2022-0675Puppet Firewall Module May Leave Unmanaged RulesPuppet Firewall Module CVE-2021-27024no title heldn/a Puppet Continuous Delivery for Puppet Enterprise (CD4PE) CVE-2021-27023no title heldn/a Puppet Enterprise, Puppet Server, Puppet Agent CVE-2020-7943no title heldn/a Resolved in Puppet Enterprise, Puppet Server, PuppetDB CVE-2018-6512no title heldPuppet Enterprise 2018.1.x prior to 2018.1.1, razor-server… CVE-2018-6511XSS Vulnerability in Puppet Enterprise ConsolePuppet Enterprise CVE-2018-6510XSS Vulnerability in Puppet Enterprise ConsolePuppet Enterprise CVE-2018-11746Puppet Discovery can leak authentication informationPuppet Discovery 51 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.