Affected versions:

- Apache Superset through 2.1.0

Description:

An improper default REST API permission for Gamma users in Apache Superset up 
to and including 2.1.0 allows for an authenticated Gamma user to test database 
connections.

Credit:

Miguel Segovia Gil (finder)

References:

https://superset.apache.org
https://www.cve.org/CVERecord?id=CVE-2023-36387

Reply via email to