Skip to main content
Question

Update Python

  • April 16, 2021
  • 29 replies
  • 155 views

Show first post

29 replies

Forum|alt.badge.img+9
  • Contributor
  • December 9, 2022

I submitted a ticket to Apple Enterprise support who informed me it was not a vulnerable application in the eyes if Apple, yet as mentioned on this thread Qualys sees the baked in version on Python installed via CLI or Xcode as a vulnerability. I think Homebrew too.

I could only defer the Vulnerabilities until Jan in the hope Ventura and Xcode 14.x update the version of python Apple use. 

**Update**

I am running Ventura and Xcode 14.1. The Python version located at /usr/bin/python is 3.9.6 which is an update from the 3.8 I had on a few months ago running Monterey.  
How long until Qualys sees 3.9.6 as a Vul?


Forum|alt.badge.img+9
  • Contributor
  • December 9, 2022

Looking at our Qualys console the suggested solution is to update to Python 3.9.5 and above.  Looks like Qualys will eventually get to 3.9.6 and I will start to see Qualys Vulnerabilities again.  

This issue will never get permanently resolved.


An exert from Qualys Detection Summary:

Python 3.9.0 /usr/bin/python3

Affected Versions:
Python Versions 3.8.0 up to 3.8.11 and 3.9.0 up to 3.9.4

Solution:

Customers are advised to install python version 3.9.5 or newer.


Forum|alt.badge.img+3
  • New Contributor
  • December 9, 2022

I submitted a ticket to Apple Enterprise support who informed me it was not a vulnerable application in the eyes if Apple, yet as mentioned on this thread Qualys sees the baked in version on Python installed via CLI or Xcode as a vulnerability. I think Homebrew too.

I could only defer the Vulnerabilities until Jan in the hope Ventura and Xcode 14.x update the version of python Apple use. 

**Update**

I am running Ventura and Xcode 14.1. The Python version located at /usr/bin/python is 3.9.6 which is an update from the 3.8 I had on a few months ago running Monterey.  
How long until Qualys sees 3.9.6 as a Vul?


3.9.6 started showing up just a few days ago, unfortunately. Thankfully we don't have many of these and if Apple sees them as not an issue then it appears there is not much we can do. This is just one of those weird things that will sit in back of my head and always be a 'what if' scenario everytime I hear about a data breach. Oh well, who needs hair? :D


Forum|alt.badge.img+9
  • Contributor
  • December 9, 2022

3.9.6 started showing up just a few days ago, unfortunately. Thankfully we don't have many of these and if Apple sees them as not an issue then it appears there is not much we can do. This is just one of those weird things that will sit in back of my head and always be a 'what if' scenario everytime I hear about a data breach. Oh well, who needs hair? :D


Bummer, thanks for update @Kevin_K   Guess I will be chatting to my boss and Security about this.  Co-workers believe Apple and Qualys should get on a call and discuss it. I still think eventually they will butt heads and nothing will come of it.