<div dir="ltr"><div>Hi,</div><div><br></div><div>It's come to my attention that our Shibboleth installation is acting as as open redirect via the Logout endpoint. For example, <a href="https://www.york.ac.uk/Shibboleth.sso/Logout?return=https://news.bbc.co.uk">https://www.york.ac.uk/Shibboleth.sso/Logout?return=https://news.bbc.co.uk</a> This could be used in phishing attacks to impersonate our domain.</div><div><br></div><div>Is this behaviour standard, or is it a mis-configuration on our part? How should we best mitigate this? One option might be to simply disable this endpoint.</div><div><br></div><div>Thanks,</div><div><br></div><div>Max Spicer</div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div style="font-size:small">Max Spicer - Identity Systems Developer</div><div style="font-size:small">Enterprise Systems Group, IT Services, University of York<br></div></div></div></div></div></div></div>