Ensuring that our IdP can not be used to redirect users to an arbitrary URL
Cantor, Scott
cantor.2 at osu.edu
Mon Feb 15 17:06:57 UTC 2021
> Are there any similar situations to be aware of with the IdP's available endpoints under 4.0?
I don't treat these as security issues so I don't think there's any exhaustive study of it. The obvious way would be promiscuous SAML or CAS configurations but that's really up to the deployer.
> I do not believe that the /profile/Logout endpoint could be exploited in this way, but I do vaguely recall that a similar
> endpoint with a return parameter did once exist in the IdP.
That's why, amongst other reasons, it isn't supported anymore.
-- Scott
More information about the users
mailing list