“Description: If the ROOT (default) web application is configured to use FORM authentication then it is possible that a specially crafted URL could be used to trigger a redirect to an URL of the attackers choice.”
'[SECURITY] CVE-2023-41080 Apache Tomcat - open redirect' - MARC https://marc.info/?l=tomcat-user&m=169298568606692&w=2