laptop and a wrench

漏洞

In Portal for ArcGIS, when using a Security Assertion Markup Language (SAML) based authentication (enterprise logins), initiating a logout from the Active Directory Federation Services (ADFS) identity provider does not log the user out of the portal.

上次发布: March 4, 2019 Portal for ArcGIS
漏洞 ID 编号 BUG-000108020
已提交September 14, 2017
上次修改时间June 5, 2024
适用范围Portal for ArcGIS
找到的版本10.4.1
操作系统Windows OS
操作系统版本2012 R2
修正版本10.7
状态Fixed

解决办法

If logouts are initiated by the identity provider, the following workaround can be used:

  1. In the Home app, export the service provider metadata file by navigating to Organization > Edit Settings > Security. Click Get Service Provider.
  2. Save the service provider metadata file to a local location and edit it using a text or XML editor.
  3. Locate the XML element "md:SingleLogoutService" and update the value of the "Location" attribute to https://[Fully qualified domain name]/[web context]/sharing/rest/oauth2/signout.
  4. Update the relying party configuration in the identity provider with this service provider metadata.

重现步骤

漏洞 ID: BUG-000108020

软件:

  • Portal for ArcGIS

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项