Impact
Feast 0.66.0 and earlier modules incorrectly accept JWT tokens without verifying their cryptographic signatures. The resulting authentication bypass allows an attacker to impersonate any user, granting complete visibility and write access to all managed entities, feature views, data sources, and permission policies. This flaw is a direct violation of role‑based access control and effectively lets an attacker take full control of the Feast server.
Affected Systems
Feast (feast-dev:feast) versions up to and including 0.66.0.
Risk and Exploitability
The nominal severity is high, with a CVSS score of 9.3, and the EPSS score of less than 1% suggests a currently low probability of exploitation. The flaw is not listed in the CISA KEV catalog, but the attack vector is inferred to be remote through the Feast API or any exposed authentication endpoint where an attacker can inject a forged token. The vulnerability’s weakness is described by CWE‑798, representing an improper verification of token signatures.
OpenCVE Enrichment