Skip to main content
Created with Avocode.

Secondary Navigation

  • Blog
  • Downloads
  • Security
  • Support
  • Contact
Home
Puppet

Main Navigation - Mega Menu

  • Products

    Get Started

    Logo Puppet Enterprise

    Free Trial

    Request Demo

    Plans and Pricing

    Puppet

    • Puppet Enterprise
    • Puppet Enterprise Advanced
    • Open Source Puppet

    Premium Features

    Impact Analysis

    Security Compliance Enforcement

    Product Resources

    • The Forge
    • Support
    • Documentation
    • What's New
  • Community

    Puppet Forge

    The Forge is your one stop location for thousands of Puppet Modules to help accelerate your automation journey. Find and manage modules here.

    Visit Puppet Forge >>

    Open Source Projects

    Open Source Puppet
    Perfect for individuals and small infrastructure

    Bolt
    Automate tasks in orchestration workflows

    See all open source projects >>

    Contribute to open source projects >>

    Community

    • Community Overview
    • Community Calendar
    • Community Slack
    • Puppet Champions
    • Puppet Test Pilots

    Ecosystem

    • GitHub
    • Integrations
    • Puppet Developer Experience
    • Trusted Contributors Program
  • Services & Training

    Services & Training

    • Professional Services
    • Support
    • Training & Education
    Person studying holding coffee mug

    Free Online Training Course

    A Brief Intro to Puppet for (Very) Busy People

    Take Course Now

  • Resources

    Resources

    • Explore Resources
    • Blog
    • Customer Stories
    • Events & Webinars
    • On-Demand Webinars
    • Papers & Videos
    • Podcast
    • Product Demos
    A graphic of a white paper by Puppet. Title: Achieving Zero Trust Security with Puppet Enterprise.

    Enforcing Better Zero Trust Security with Puppet Enterprise

    Read Now
  • Why Puppet

    Why Puppet

    • Why Puppet
    • Compare Puppet
    • Customer Stories
    • Press

    By Use Case

    • Application Delivery & Operations
    • Continuous Compliance
    • Continuous Configuration Automation
    • Hybrid Cloud Management
    • IT Process Automation & Orchestration
    • Patch Management
    • Windows Infrastructure Automation
  • Try Puppet
  • Products

    Main Navigation - Mega Menu

    • Explore Products

    Main Navigation - Mega Menu

    • Get Started
    • Puppet
    • Premium Features
    • Resources

    Main Navigation - Mega Menu

    • Puppet Enterprise
    • Open Source Puppet
    • Puppet Enterprise Advanced

    Main Navigation - Mega Menu

    • Impact Analysis
    • Security Compliance Enforcement

    Main Navigation - Mega Menu

    • The Forge
    • Support
    • Documentation
    • What's New

    Main Navigation - Mega Menu

    • Free Trial
    • Plans and Pricing
    • Request A Demo
    • Explore Products
  • Community

    Main Navigation - Mega Menu

    • Explore Community

    Main Navigation - Mega Menu

    • Puppet Forge
    • Open Source Projects
    • Community
    • Ecosystem

    Main Navigation - Mega Menu

    • Puppet Forge

    Main Navigation - Mega Menu

    • Bolt
    • Contribute to Open Source Projects
    • Open Source Puppet
    • See All Open Source Projects

    Main Navigation - Mega Menu

    • Community Calendar
    • Community Overview
    • Community Slack
    • Puppet Champions
    • Puppet Test Pilots

    Main Navigation - Mega Menu

    • Github
    • Integrations
    • Puppet Developer Experience
    • Trusted Contributors Program
    • Explore Community
  • Why Puppet

    Main Navigation - Mega Menu

    • Explore Why

    Main Navigation - Mega Menu

    • Why Puppet
    • By Use Case

    Main Navigation - Mega Menu

    • Compare Puppet
    • Press
    • Why Puppet
    • Customer Stories

    Main Navigation - Mega Menu

    • Application Delivery & Operations
    • Hybrid Cloud Management
    • Continuous Compliance
    • Continuous Configuration Automation
    • Government
    • IT Process Automation & Orchestration
    • Patch Management
    • Windows Infrastructure Automation
    • Explore Why
  • Services & Training

    Main Navigation - Mega Menu

    • Professional Services
    • Support
    • Training & Education
    Person studying holding coffee mug

    Free Online Training Course

    A Brief Intro to Puppet for (Very) Busy People

    Take Course Now

  • Resources

    Main Navigation - Mega Menu

    • Blog
    • Customer Stories
    • Events & Webinars
    • On-Demand Webinars
    • Papers & Videos
    • Podcast
    • Product Demos
    A graphic of a white paper by Puppet. Title: Achieving Zero Trust Security with Puppet Enterprise.

    Enforcing Better Zero Trust Security with Puppet Enterprise

    Read Now
  • Try Puppet
  • Blog
  • Contact

SECURITY MAIN

Security: Puppet's Vulnerability Submission Process

 

Looking for Historical CVE Information? 
Click the CVE List button to view our new CVE Listing page. 

CVE LIST 
 

 

Security Policy

Puppet supports coordinated disclosure of security vulnerabilities and welcomes reports from security researchers on issues found in Puppet products, and Puppet distributed packages or infrastructure.

Out-of-Scope:

  • Software version or banner disclosures
  • Directory traversal on yum, apt, or downloads.puppet.com where traversal is explicitly desired
  • Self-XSS or CSRF on unauthenticated web forms (including logout CSRF)
  • Disclosure or discovery of known public files or directories (for example, robots.txt, simple DNS enumeration)
  • Brute force attempts (for example, log-in and forgot password pages don’t have lockouts)
  • Account enumeration (for example, enumerating login or reset fields for valid accounts without lockouts)
  • Email spoofing possibilities. Suggesting turning on SPF, DMARC, or DKIM isn’t welcome, though specific issues with those configurations are.

To report a vulnerability contact the Puppet security team at security@perforce.com.

Contact the Puppet security team via encrypted communication using our PGP Public key:

Puppet Security Team
Key Long-format ID: 8728524FE21D3FC6
Key Fingerprint: 489C F9E6 BB24 2589 EFF5 BB68 8728 524F E21D 3FC6

 

The key is available in ASCII encoded format. It can also be retrieved and verified from the MIT Key Server.

We credit security researchers based on the value of the contributions they provide. The Puppet security team reviews each disclosure and assigns a scored value based on the relevance of the disclosure. These scores are calculated quarterly, and the top-scoring individuals are publicly credited on our website. Additional credit will be awarded to individuals who provide code fixes or additional information about how to fix the vulnerability.

Thank you for supporting Puppet’s coordinated disclosure process!

Puppet Security

Footer menu

  • Products
    • Puppet
      • Open Source Puppet
      • Puppet Enterprise
      • Puppet Enterprise Advanced
      • Plans & Pricing
    • Get Started
      • Request a Demo
      • Free Puppet Enterprise Trial
    • Puppet Premium Features
      • Security Compliance Enforcement
      • Impact Analysis
    • Product Resources
      • Documentation
      • Integrations
      • Resources & Modules
      • Content & Tooling
      • Knowledge Base
      • Support
  • Community
    • Puppet Forge
      • Puppet Forge
    • Open Source Projects
      • See All Open Source Projects
      • Open Source Puppet
      • Bolt
      • Contribute to Open Source Projects
    • Community
      • Community Calendar
      • Community Overview
      • Community Slack
      • Puppet Champions
      • Puppet Test Pilots
    • Ecosystem
      • GitHub
      • Integrations
      • Puppet Developer Experience
      • Trusted Contributors Program
  • Why Puppet
    • Why Puppet
      • Compare Puppet
      • Customer Stories
      • Press
      • Why Puppet
    • By Use Case
      • Application Delivery & Operations
      • Continuous Compliance
      • Continuous Configuration Automation
      • Government
      • IT Process Automation & Orchestration
      • Patch Management
      • Windows Infrastructure Automation
  • Services & Training
    • Professional Services
      • Admin as a Service
      • Black Belt
      • Technical Account Manager (PDF)
      • Support
      • Training & Education
  • Resources
    • Blog
    • Customer Stories
    • Events & Webinars
    • On-Demand Webinars
    • Papers & Videos
    • Podcast
    • Product Demos
Home

Puppet by Perforce © Perforce Software, Inc.
Terms & Conditions | Privacy Policy | Sitemap

Social Menu

  • Facebook
  • Twitter
  • LinkedIn
  • YouTube
  • Slack
  • RSS
Send Feedback