Apache Superset through 1.3.2 contains a default login vulnerability via registered database connections for authenticated users. An attacker can obtain access to user accounts and thereby obtain sensitive information, modify data, and/or execute unauthorized operations.
id: CVE-2021-44451
info:
name: Apache Superset <=1.3.2 - Default Login
author: dhiyaneshDK
se
...