Puppetdb Puppetdb

Do you want an email whenever new security vulnerabilities are reported in Puppetdb?

By the Year

In 2024 there have been 0 vulnerabilities in Puppetdb . Puppetdb did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 0 0.00
2021 2 6.55
2020 1 7.50
2019 0 0.00
2018 0 0.00

It may take a day or so for new Puppetdb vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Puppetdb Security Vulnerabilities

PuppetDB logging included potentially sensitive system information.

CVE-2021-27019 4.3 - Medium - August 30, 2021

PuppetDB logging included potentially sensitive system information.

Insertion of Sensitive Information into Log File

A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which

CVE-2021-27021 8.8 - High - July 20, 2021

A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.

SQL Injection

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints

CVE-2020-7943 7.5 - High - March 11, 2020

Puppet Server and PuppetDB provide useful performance and debugging information via their metrics API endpoints. For PuppetDB this may contain things like hostnames. Puppet Server reports resource names and titles for defined types (which may contain sensitive information) as well as function names and class names. Previously, these endpoints were open to the local network. PE 2018.1.13 & 2019.5.0, Puppet Server 6.9.2 & 5.3.12, and PuppetDB 6.9.1 & 5.2.13 disable trapperkeeper-metrics /v1 metrics API and only allows /v2 access on localhost by default. This affects software versions: Puppet Enterprise 2018.1.x stream prior to 2018.1.13 Puppet Enterprise prior to 2019.5.0 Puppet Server prior to 6.9.2 Puppet Server prior to 5.3.12 PuppetDB prior to 6.9.1 PuppetDB prior to 5.2.13 Resolved in: Puppet Enterprise 2018.1.13 Puppet Enterprise 2019.5.0 Puppet Server 6.9.2 Puppet Server 5.3.12 PuppetDB 6.9.1 PuppetDB 5.2.13

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Puppet Enterprise or by Puppet? Click the Watch button to subscribe.

Puppet
Vendor

Puppetdb
Product

subscribe