CyberRota Analysis
AI-GeneratedAn authorization bypass vulnerability in Feast's /materialize and /materialize-incremental endpoints allows attackers to circumvent permission checks by sending specially crafted requests that omit the feature_views field. This can lead to a Denial of Service (DoS) through data corruption and excessive resource consumption, affecting all tenants. Organizations using Feast should prioritize addressing this vulnerability to prevent potential service disruptions and resource exhaustion.
Original NVD Description
A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a specially crafted request that omits the feature_views field, an attacker can bypass intended permission checks. This allows an unauthenticated remote attacker, or any authenticated user, to trigger a full re-materialization of all feature views. The consequence is a Denial of Service (DoS) due to data corruption and significant resource consumption across all tenants.