An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
{ "cpes": [ "cpe:2.3:a:apache:superset:*:*:*:*:*:*:*:*" ], "severity": "Medium" }