Description
Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs
Problem types
CWE‑601: URL Redirection to Untrusted Site (“Open Redirect”)
Product status
10.5.0 (semver)
10.11.0
10.5.10
Credits
Juho Forsén 
References
mattermost.com/security-updates