Impact of CVE-2021-29923 and CVE-2021-36221 on Mender

Hi there!

How do you consider the impact of

https://nvd.nist.gov/vuln/detail/CVE-2021-29923
https://nvd.nist.gov/vuln/detail/CVE-2021-36221

on Mender?

Do you think this is critical? We are asking since dunfell is directly affected with version 1.14.12.

Best regards

Not affected, I believe. Mender neither uses ReverseProxy nor IP based access control.

1 Like