{"id":"ECHO-a985-43d5-9a0c","upstream":["CVE-2024-7701"],"severity":[],"modified":"2026-10-08T16:30:05.304Z","affected":[{"package":{"ecosystem":"Echo","name":"percona-toolkit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.7.1+e2"}]}]}],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2024-7701"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2024-7701"}],"withdrawn":"2026-10-08T16:30:05.304Z","summary":"GHSA-r44j-crv5-q35m / NVD's own CPE match pins this to the single\nexact version percona-toolkit:3.6.0, with no version range -- the\nadvisory is \"unreviewed\" and carries no upper bound, so CPE-based\nscanners (Trivy/Grype/Wiz) treat it as affecting every later version\ntoo. The vulnerable code (weak SHA-256-as-KDF password hashing in\nsrc/go/pt-secure-collect/encrypt.go) was replaced with a proper HKDF\nderivation upstream in commit 78f20304 (\"Use KDF instead of hash\"),\nfirst shipped in v3.7.0 and present in our v3.7.1 build. Independent\nof the version question, this package never builds pt-secure-collect\nat all -- only pt-online-schema-change (a separate Perl tool); the\nbuild step explicitly drops the manifypods->gotools coupling so Go\ntools are never compiled.\n"}