Mattermost fails to properly check a redirect URL parameter allowing for an open redirect was possible when the user clicked "Back to Mattermost" after providing a invalid custom url scheme in /oauth/{service}/mobilelogin?redirectto=
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-47168.json"