{"id":"ECHO-a985-43d5-9a0c","summary":"GHSA-r44j-crv5-q35m / NVD's own CPE match pins this to the single\nexact version percona-toolkit:3.6.0, with no version range -- the\nadvisory is \"unreviewed\" and carries no upper bound, so CPE-based\nscanners (Trivy/Grype/Wiz) treat it as affecting every later version\ntoo. The vulnerable code (weak SHA-256-as-KDF password hashing in\nsrc/go/pt-secure-collect/encrypt.go) was replaced with a proper HKDF\nderivation upstream in commit 78f20304 (\"Use KDF instead of hash\"),\nfirst shipped in v3.7.0 and present in our v3.7.1 build. Independent\nof the version question, this package never builds pt-secure-collect\nat all -- only pt-online-schema-change (a separate Perl tool); the\nbuild step explicitly drops the manifypods-\u003egotools coupling so Go\ntools are never compiled.\n","modified":"2026-10-08T17:30:21.929404922Z","published":"2026-10-08T14:59:47.564Z","withdrawn":"2026-10-08T16:30:05.304Z","upstream":["CVE-2024-7701"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2024-7701"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2024-7701"}],"affected":[{"package":{"name":"percona-toolkit","ecosystem":"Echo","purl":"pkg:deb/echo/percona-toolkit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.7.1+e2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-a985-43d5-9a0c.json"}}],"schema_version":"1.9.0"}