Skip to content

Synk vulnerabilities on Feast pip #6810

Description

@shyamaryan

4 vulnerabilities are detected in Synk vulnerability database. Please help to fix all these in the upcoming release.
https://security.snyk.io/package/pip/feast

https://security.snyk.io/vuln/SNYK-PYTHON-FEAST-9510933
Affected versions of this package are vulnerable to Origin Validation Error due to improper CORS configuration on the server. An attacker can bypass security controls and potentially access sensitive information by sending requests from unauthorized origins.

https://security.snyk.io/vuln/SNYK-PYTHON-FEAST-18612609
Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the registry’s user-defined function handling in the registry server and feature server components. An attacker can execute arbitrary code by storing a malicious serialized UDF in the registry and causing it to be deserialized. In default deployments, this leads to unauthenticated code execution on the feature server, and an authenticated attacker can also execute code on the registry server by abusing the deserialization path, enabling cross-tenant data access and lateral movement.

https://security.snyk.io/vuln/SNYK-PYTHON-FEAST-18612610
Affected versions of this package are vulnerable to Incorrect Behavior Order: Early Amplification in the /materialize and /materialize-incremental endpoints. An attacker can trigger a full re-materialization of all feature views, causing denial of service, by sending a specially crafted request that omits the feature_views field. This bypasses the intended permission checks for those endpoints and can be exercised by an unauthenticated remote attacker or any authenticated user. The result is significant resource consumption and data corruption that disrupts service for all tenants.

https://security.snyk.io/vuln/SNYK-PYTHON-FEAST-18612620
Affected versions of this package are vulnerable to Missing Authentication for Critical Function through the feature-server, registry-server, and offline-server endpoints when the default no_auth configuration leaves no security manager installed. An attacker can gain unauthorized access, execute arbitrary code, and trigger denial of service by sending requests to these exposed endpoints, including storing a malicious User-Defined Function on the feature-server or forcing re-materialization of all tenant features. This exposes cross-tenant feature data and can disrupt service for affected users and tenants.

Impact
These are vulnerabilities reported in Synk vulnerability database with high - medium severity.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions