The vendor explicitly identifies these products as affected by this CVE.
- mta/mta-solution-server-rhel9 as a component of Migration Toolkit for Applications 8
- rhoai/odh-feature-server-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-th06-cpu-torch210-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-th06-cpu-torch291-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-th06-cuda130-torch210-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-th06-cuda130-torch291-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-th06-rocm64-torch291-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9 as a component of Red Hat OpenShift AI (RHOAI)
- Summary
- A flaw was found in JupyterLab where a missing 'await' in the `PyPIExtensionManager.install()` function could lead to an allowlist/blocklist enforcement gap. This vulnerability allows direct callers of `install()` to bypass security checks, potentially enabling the installation of unauthorized extensions. This issue affects deployments where a custom extension or downstream integration calls `install()` directly with untrusted input, an allowlist/blocklist is configured, and the PyPI Extension Manager is enabled.
- Remediation
- Fix deferred
