@Begize
We are in the same boat and feeling the same pain on our side. We are seeing the exact same Qualys findings against the Python 3.9.6 runtime bundled with Apple's Command Line Tools. We've also found that even after manually deleting the Python 3.9.6 version, it eventually gets recreated automatically as part of the CLT/Xcode tooling, so removal is not a permanent solution.
Like you, we noticed these are mostly older CVEs that suddenly started appearing this year despite existing in the environment for a long time. This strongly suggests a change in Qualys detection logic rather than a newly introduced vulnerability.
Unfortunately, we're stuck in the same position: patching the bundled Python instance is not supported by Apple, deleting it is ineffective because it comes back, and removing CLT altogether is not a realistic option for developer machines. At this point, we're essentially waiting on either Apple to release an updated CLT package or Qualys to provide additional guidance, an exception, or a correction to the detection logic if it is ultimately determined to be a false positive.
So, unfortunately, we're sharing the same frustration and currently don't have a practical remediation path available.
Topic:
Developer Tools & Services
SubTopic:
Xcode
Tags: