Post

Replies

Boosts

Views

Activity

Reply to Command Line Tools bundled Python 3.9.6 flagged by vulnerability scanner
Just to add some more info, we have 9 different Qualys vulns, all apparently with this same Python bundled with command line tools. It's interesting they are mostly based on old (2023) CVE's, and they have not flagged on our estate until June / July this year, so Qualys hasn't previously detected them in CLT and I imagine Qualys have made a recent (assumed deliberate) change to their detection logic which now picks them up. I raised it with Qualys support, making the argument that the Python runtime is not technically vulnerable the way it is installed and used by XCode and asking if they could explain why they changed the logic and if we could somehow whitelist that particular file path given that patching outside of official Apple updates is effectively impossible without breaking things. Qualys accepted that the detection is probably a false positive (they gave me no indication of when or why they changed their detection rules) and agreed that patching is not an option. They have "reached out" to Apple for more information and clarification but as yet have had no reply. Qualys have said there is no way to whitelist a file, only the whole vulnerability (which is obviously risky on developer machines with Python installed elsewhere as we are dealing with). At the moment there is nothing we can do except remove CLT from devices or wait for Apple to provide an updated Python instance or information to Qualys explaining how it is used and isn't vulnerable. Their only suggested "fix" is to remove CLT.
2w
Reply to Command Line Tools bundled Python 3.9.6 flagged by vulnerability scanner
Just to add some more info, we have 9 different Qualys vulns, all apparently with this same Python bundled with command line tools. It's interesting they are mostly based on old (2023) CVE's, and they have not flagged on our estate until June / July this year, so Qualys hasn't previously detected them in CLT and I imagine Qualys have made a recent (assumed deliberate) change to their detection logic which now picks them up. I raised it with Qualys support, making the argument that the Python runtime is not technically vulnerable the way it is installed and used by XCode and asking if they could explain why they changed the logic and if we could somehow whitelist that particular file path given that patching outside of official Apple updates is effectively impossible without breaking things. Qualys accepted that the detection is probably a false positive (they gave me no indication of when or why they changed their detection rules) and agreed that patching is not an option. They have "reached out" to Apple for more information and clarification but as yet have had no reply. Qualys have said there is no way to whitelist a file, only the whole vulnerability (which is obviously risky on developer machines with Python installed elsewhere as we are dealing with). At the moment there is nothing we can do except remove CLT from devices or wait for Apple to provide an updated Python instance or information to Qualys explaining how it is used and isn't vulnerable. Their only suggested "fix" is to remove CLT.
Replies
Boosts
Views
Activity
2w