Impact
A flaw was discovered in Feast whereby the /materialize and /materialize-incremental endpoints do not verify the presence of the feature_views field before performing a full re-materialization. This omission permits an attacker to send a request that bypasses established permission checks, enabling them to initiate a complete re-materialization of all feature views. The resulting process consumes significant compute and storage resources, corrupts data, and can render the service unavailable. This vulnerability represents an improper access control weakness that can lead to denial of service, particularly affecting multi-tenant environments.
Affected Systems
Red Hat OpenShift AI (RHOAI). No specific version information was supplied by the CNA, so the advisory applies to all releases of the product as documented in the CNA vendor list.
Risk and Exploitability
The CVSS score of 8.5 classifies this issue as high severity, indicating a substantial impact if exploited. Although the EPSS score is not provided, the absence of a KEV entry suggests no currently documented exploits, but the flaw can be triggered remotely via crafted HTTP requests to the Feast feature server. Because the bypass allows both unauthenticated and authenticated users to launch the resource‑intensive operation, the threat model includes anyone who can reach the server, underscoring the need for immediate mitigation.
OpenCVE Enrichment