MEDIUM 4.3 Go
Mattermost Open Redirect vulnerability
GHSA-4ghx-8jw8-p76q · CVE-2023-47168
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes