Vulnerability Description
Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobile_login?redirect_to=
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mattermost | Mattermost | <= 7.8.12 |
Related Weaknesses (CWE)
References
- https://mattermost.com/security-updatesVendor Advisory
- https://mattermost.com/security-updatesVendor Advisory
FAQ
What is CVE-2023-47168?
CVE-2023-47168 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/...
How severe is CVE-2023-47168?
CVE-2023-47168 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-47168?
Check the references section above for vendor advisories and patch information. Affected products include: Mattermost Mattermost.