# Impact of CVE-2020-29510 on Mender

**URL:** <https://hub.mender.io/t/impact-of-cve-2020-29510-on-mender/3140>\
**Category:** General Discussions\
**Tags:** yocto, warrior, security\
**Created:** [January 27, 2021, 2:45pm UTC](https://hub.mender.io/t/impact-of-cve-2020-29510-on-mender/3140 "2021-01-27T14:45:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![deffo](https://avatars.discourse-cdn.com/v4/letter/d/ec9cab/32.png) [@deffo](https://hub.mender.io/u/deffo)\
**Post date:** [January 27, 2021, 2:45pm UTC](https://hub.mender.io/t/impact-of-cve-2020-29510-on-mender/3140/1 "2021-01-27T14:45:36Z")

</div>

Hi there!

How do you consider the impact of CVE-2020-29510 [1] on Mender? Do you think this is critical? We are asking since warrior-v2020.10 is directly affected with version 1.14.7.

Best regards

[1] [NVD - CVE-2020-29510](https://nvd.nist.gov/vuln/detail/CVE-2020-29510)

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [January 29, 2021, 8:05pm UTC](https://hub.mender.io/t/impact-of-cve-2020-29510-on-mender/3140/2 "2021-01-29T20:05:03Z")

</div>

@kacf any thoughts on this?

---

<div class="post-metadata">

**Author:** ![kacf](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/kacf/32/146_2.png) [@kacf](https://hub.mender.io/u/kacf)\
**Post date:** [February 1, 2021, 8:07am UTC](https://hub.mender.io/t/impact-of-cve-2020-29510-on-mender/3140/3 "2021-02-01T08:07:20Z")

</div>

Hello @deffo, neither the Mender Client nor Mender Connect uses `encoding/xml` anywhere, including in sub packages, so I believe they are not affected.
