Impact
The Feast operator has a flaw that permits a tenant to inject arbitrary code into the feature repository. The injected code is executed automatically by a cronjob running with elevated privileges, enabling the tenant to exfiltrate credentials. This can lead to direct administrative control over the cluster.
Affected Systems
The vulnerability affects Red Hat OpenShift AI deployments that incorporate the Feast operator. No specific version numbers are provided, so any installation of the RHOAI Feast operator remains at risk until patched.
Risk and Exploitability
The CVSS score is 5.5, indicating a moderate risk. EPSS is not available, and it is not listed in the CISA KEV catalog. The likely attack vector would involve a tenant with write access to the feature repository. By adding malicious code to the repository, the tenant triggers execution in a cronjob pod, which has broader cluster privileges. Successful exploitation would grant the malicious tenant administrative rights.
OpenCVE Enrichment