Ensuring that our IdP can not be used to redirect users to an arbitrary URL

Cantor, Scott cantor.2 at osu.edu
Mon Feb 15 17:06:57 UTC 2021


>    Are there any similar situations to be aware of with the IdP's available endpoints under 4.0?

I don't treat these as security issues so I don't think there's any exhaustive study of it. The obvious way would be promiscuous SAML or CAS configurations but that's really up to the deployer.

> I do not believe that the /profile/Logout endpoint could be exploited in this way, but I do vaguely recall that a similar
> endpoint with a return parameter did once exist in the IdP.

That's why, amongst other reasons, it isn't supported anymore.

-- Scott




More information about the users mailing list