Feast Feature Server
- <= 0.58.0
A denial-of-service vulnerability has been identified in the Feast Feature Server, specifically within the '/ws/chat' WebSocket endpoint. This issue allows remote attackers to establish persistent WebSocket connections without authentication. By opening numerous simultaneous connections, an attacker can deplete server resources such as memory, CPU, and file descriptors, causing a complete denial of service for legitimate users. The vulnerability affects Feast Feature Server versions through 0.58.0.
Exploitation of this vulnerability leads to resource exhaustion, causing high CPU and memory usage, and consuming file descriptors. This resource depletion disrupts service for legitimate users, causing a denial-of-service condition.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.