Skip to main content
Question

Update Python


Show first post

29 replies

Forum|alt.badge.img+9
  • Contributor
  • 127 replies
  • December 9, 2022

I submitted a ticket to Apple Enterprise support who informed me it was not a vulnerable application in the eyes if Apple, yet as mentioned on this thread Qualys sees the baked in version on Python installed via CLI or Xcode as a vulnerability. I think Homebrew too.

I could only defer the Vulnerabilities until Jan in the hope Ventura and Xcode 14.x update the version of python Apple use. 

**Update**

I am running Ventura and Xcode 14.1. The Python version located at /usr/bin/python is 3.9.6 which is an update from the 3.8 I had on a few months ago running Monterey.  
How long until Qualys sees 3.9.6 as a Vul?


Forum|alt.badge.img+9
  • Contributor
  • 127 replies
  • December 9, 2022

Looking at our Qualys console the suggested solution is to update to Python 3.9.5 and above.  Looks like Qualys will eventually get to 3.9.6 and I will start to see Qualys Vulnerabilities again.  

This issue will never get permanently resolved.


An exert from Qualys Detection Summary:

Python 3.9.0 /usr/bin/python3

Affected Versions:
Python Versions 3.8.0 up to 3.8.11 and 3.9.0 up to 3.9.4

Solution:

Customers are advised to install python version 3.9.5 or newer.


Forum|alt.badge.img+3
  • New Contributor
  • 5 replies
  • December 9, 2022
pueo wrote:

I submitted a ticket to Apple Enterprise support who informed me it was not a vulnerable application in the eyes if Apple, yet as mentioned on this thread Qualys sees the baked in version on Python installed via CLI or Xcode as a vulnerability. I think Homebrew too.

I could only defer the Vulnerabilities until Jan in the hope Ventura and Xcode 14.x update the version of python Apple use. 

**Update**

I am running Ventura and Xcode 14.1. The Python version located at /usr/bin/python is 3.9.6 which is an update from the 3.8 I had on a few months ago running Monterey.  
How long until Qualys sees 3.9.6 as a Vul?


3.9.6 started showing up just a few days ago, unfortunately. Thankfully we don't have many of these and if Apple sees them as not an issue then it appears there is not much we can do. This is just one of those weird things that will sit in back of my head and always be a 'what if' scenario everytime I hear about a data breach. Oh well, who needs hair? :D


Forum|alt.badge.img+9
  • Contributor
  • 127 replies
  • December 9, 2022
Kevin_K wrote:

3.9.6 started showing up just a few days ago, unfortunately. Thankfully we don't have many of these and if Apple sees them as not an issue then it appears there is not much we can do. This is just one of those weird things that will sit in back of my head and always be a 'what if' scenario everytime I hear about a data breach. Oh well, who needs hair? :D


Bummer, thanks for update @Kevin_K   Guess I will be chatting to my boss and Security about this.  Co-workers believe Apple and Qualys should get on a call and discuss it. I still think eventually they will butt heads and nothing will come of it.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings