An improper default REST API permission for Gamma users in Apache Superset up to and including 2.1.0 allows for an authenticated Gamma user to test database connections.
{ "nvd_published_at": "2023-09-06T13:15:08Z", "cwe_ids": [ "CWE-281", "CWE-863", "CWE-918" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-09-07T13:59:27Z" }