# Impact of CVE-2021-31525 and CVE-2021-33194 on Mender

**URL:** <https://hub.mender.io/t/impact-of-cve-2021-31525-and-cve-2021-33194-on-mender/3821>\
**Category:** General Discussions\
**Tags:** security\
**Created:** [July 2, 2021, 12:55pm UTC](https://hub.mender.io/t/impact-of-cve-2021-31525-and-cve-2021-33194-on-mender/3821 "2021-07-02T12:55:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![deffo](https://avatars.discourse-cdn.com/v4/letter/d/ec9cab/32.png) [@deffo](https://hub.mender.io/u/deffo)\
**Post date:** [July 2, 2021, 12:55pm UTC](https://hub.mender.io/t/impact-of-cve-2021-31525-and-cve-2021-33194-on-mender/3821/1 "2021-07-02T12:55:38Z")

</div>

Hi there!

How do you consider the impact of CVE-2021-31525 [1] and CVE-2021-33194 [2] on Mender? Do you think this is critical?

Best regards

[1] [NVD - CVE-2021-31525](https://nvd.nist.gov/vuln/detail/CVE-2021-31525)  
[2] [NVD - CVE-2021-33194](https://nvd.nist.gov/vuln/detail/CVE-2021-33194)

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [July 2, 2021, 1:39pm UTC](https://hub.mender.io/t/impact-of-cve-2021-31525-and-cve-2021-33194-on-mender/3821/2 "2021-07-02T13:39:08Z")

</div>

@kacf do you have any thoughts here?

---

<div class="post-metadata">

**Author:** ![tranchitella](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/tranchitella/32/606_2.png) [@tranchitella](https://hub.mender.io/u/tranchitella)\
**Post date:** [July 2, 2021, 1:46pm UTC](https://hub.mender.io/t/impact-of-cve-2021-31525-and-cve-2021-33194-on-mender/3821/3 "2021-07-02T13:46:22Z")

</div>

The impact on the client is extremely low, as it only connects to the Mender server it trusts.  
On the backend-side, it needs a bit of investigation to see which version is affected.  
I’ll get back to this thread early next week.
