Product
Feast and feast-operator contain a vulnerability due to a default 'no_auth' configuration, allowing unauthenticated attackers to achieve RCE via malicious User-Defined Functions and perform unauthorized cross-tenant data access.