# CVE-2021-3121 and CVE-2021-38561

**URL:** <https://forums.percona.com/t/cve-2021-3121-and-cve-2021-38561/16438>\
**Category:** Percona Toolkit\
**Created:** [July 5, 2022, 2:28pm UTC](https://forums.percona.com/t/cve-2021-3121-and-cve-2021-38561/16438 "2022-07-05T14:28:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kin](https://avatars.discourse-cdn.com/v4/letter/k/b9e5f3/32.png) [@Kin](https://forums.percona.com/u/Kin)\
**Post date:** [July 5, 2022, 2:28pm UTC](https://forums.percona.com/t/cve-2021-3121-and-cve-2021-38561/16438/1 "2022-07-05T14:28:36Z")

</div>

Hi there, I tried to build the mysql-operator-sidecar-5.7 image, but I have encountered two CVE’s after scanning with Trivy:  
CVE-2021-3121 (high), CVE-2021-38561 (high)

These (golang) libraries seem to be related with a few binaries from the Percona Toolkit:  
pt-k8s-debug-collector  
pt-mongodb-query-digest  
pt-mongodb-summary

Does this have security impact or can we whitelist them?

Both libraries have fixed versions.

---

<div class="post-metadata">

**Author:** ![Kin](https://avatars.discourse-cdn.com/v4/letter/k/b9e5f3/32.png) [@Kin](https://forums.percona.com/u/Kin)\
**Post date:** [July 6, 2022, 8:23am UTC](https://forums.percona.com/t/cve-2021-3121-and-cve-2021-38561/16438/2 "2022-07-06T08:23:13Z")

</div>

For now, I had to rebuild the binaries for linux\_amd64 at percona-toolkit/src/go. This seems to have built with the fixed versions of the libraries. Copied the binaries to a forked sidecar 5.7 image and ran trivy scan without vulnerabilities.  
Ofcourse this is a temporary solution in order to fullfill security requirements.
