0.66.0.dev69
7 years ago
18 hours ago
Known vulnerabilities in the feast package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
feast is a Python SDK for Feast Affected versions of this package are vulnerable to Missing Authentication for Critical Function through the feature-server, registry-server, and offline-server endpoints when the default Notes
How to fix Missing Authentication for Critical Function? There is no fixed version for | [0,) |
feast is a Python SDK for Feast Affected versions of this package are vulnerable to Incorrect Behavior Order: Early Amplification in the Notes
How to fix Incorrect Behavior Order: Early Amplification? There is no fixed version for | [0,) |
feast is a Python SDK for Feast Affected versions of this package are vulnerable to Deserialization of Untrusted Data through the registry’s user-defined function handling in the registry server and feature server components. An attacker can execute arbitrary code by storing a malicious serialized UDF in the registry and causing it to be deserialized. In default deployments, this leads to unauthenticated code execution on the feature server, and an authenticated attacker can also execute code on the registry server by abusing the deserialization path, enabling cross-tenant data access and lateral movement. Notes
How to fix Deserialization of Untrusted Data? There is no fixed version for | [0,) |
feast is a Python SDK for Feast Affected versions of this package are vulnerable to Origin Validation Error due to improper CORS configuration on the server. An attacker can bypass security controls and potentially access sensitive information by sending requests from unauthorized origins. How to fix Origin Validation Error? There is no fixed version for | [0,) |