CVE-2023-47168: URL Redirection to Untrusted Site ('Open Redirect')
(updated )
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked “Back to Mattermost” after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
References
Detect and mitigate CVE-2023-47168 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →