Impact
A flaw was discovered in Feast whereby the /materialize and /materialize-incremental endpoints do not verify the presence of the feature_views field before performing a full re-materialization. This omission permits an attacker to send a request that bypasses established permission checks, enabling them to initiate a complete re-materialization of all feature views. The resulting process consumes significant compute and storage resources, corrupts data, and can render the service unavailable. This vulnerability represents an improper access control weakness that can lead to denial of service, particularly affecting multi-tenant environments.
Affected Systems
Red Hat OpenShift AI (RHOAI). The vulnerability affects the 2.25 and 3.3 releases, as identified by the vendor via the provided CPE strings.
Risk and Exploitability
The CVSS score of 8.5 classifies this issue as high severity, indicating a substantial impact if exploited. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, which is consistent with its absence from the KEV catalog. The flaw can be triggered remotely via crafted HTTP requests to the Feast feature server. Because the bypass allows both unauthenticated and authenticated users to launch the resource‑intensive operation, the threat model includes anyone who can reach the server, underscoring the need for immediate mitigation.
OpenCVE Enrichment