VDB
KO
MEDIUM

GHSA-h5v5-8746-g7mm

JupyterLab PluginManager lock-rule enforcement bypass

Quick fix

GHSA-h5v5-8746-g7mm — jupyterlab: upgrade to the fixed version with the command below.

pip install --upgrade 'jupyterlab>=4.6.2'

Details

JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to `/lab/api/plugins`.

### Impact

Users could workaround the plugin manager lock rules via direct API access for either: - child plugins of extensions covering multiple plugins - when "lock all" was issued by the administrator

The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms.

### Patches

JupyterLab [`v4.6.2`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2) and [`v4.5.10`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10) contain the patch.

Users of applications that depend on JupyterLab, such as Notebook v7+, should update `jupyterlab` package too.

### Workarounds

Manually lock all plugins that should be locked. The core plugin identifiers can be found in [the documentation](https://jupyterlab.readthedocs.io/en/latest/extension/extension_points.html#core-plugins) and identifiers for all installed extensions are listed in the [Plugin Manager](https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#managing-plugins-with-plugin-manager).

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / jupyterlab
Introduced in: 4.6.0 Fixed in: 4.6.2
Fix pip install --upgrade 'jupyterlab>=4.6.2'
PyPI / jupyterlab
Introduced in: 4.1.0 Fixed in: 4.5.10
Fix pip install --upgrade 'jupyterlab>=4.5.10'

References