VDB
EN
MEDIUM

GHSA-h5v5-8746-g7mm

JupyterLab PluginManager lock-rule enforcement bypass

빠른 조치

GHSA-h5v5-8746-g7mm — jupyterlab: 아래 명령으로 수정 버전으로 올리세요.

pip install --upgrade 'jupyterlab>=4.6.2'

상세

JupyterLab's plugin manager exposes administrator controls intended to prevent users from enabling or disabling selected plugins. Two server-side enforcement gaps let an authenticated user bypass those controls with direct requests to `/lab/api/plugins`.

### Impact

Users could workaround the plugin manager lock rules via direct API access for either: - child plugins of extensions covering multiple plugins - when "lock all" was issued by the administrator

The integrity of data can be impacted, and any hardening or restrictions on permitted user actions (e.g. download/upload limits) within the single-user server can be circumvented if those were implemented with plugins that were locked using the faulty mechanisms.

### Patches

JupyterLab [`v4.6.2`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.6.2) and [`v4.5.10`](https://github.com/jupyterlab/jupyterlab/releases/tag/v4.5.10) contain the patch.

Users of applications that depend on JupyterLab, such as Notebook v7+, should update `jupyterlab` package too.

### Workarounds

Manually lock all plugins that should be locked. The core plugin identifiers can be found in [the documentation](https://jupyterlab.readthedocs.io/en/latest/extension/extension_points.html#core-plugins) and identifiers for all installed extensions are listed in the [Plugin Manager](https://jupyterlab.readthedocs.io/en/latest/user/extensions.html#managing-plugins-with-plugin-manager).

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

PyPI / jupyterlab
최초 영향 버전: 4.6.0 수정 버전: 4.6.2
수정 pip install --upgrade 'jupyterlab>=4.6.2'
PyPI / jupyterlab
최초 영향 버전: 4.1.0 수정 버전: 4.5.10
수정 pip install --upgrade 'jupyterlab>=4.5.10'

참고