laptop and a wrench

漏洞

When specifying a logout endpoint URL (SAML or OIDC) containing URL parameters, an invalid request to the logout endpoint URL is constructed.

Portal for ArcGIS
漏洞 ID 编号 BUG-000160730
已提交August 16, 2023
上次修改时间June 10, 2025
适用范围Portal for ArcGIS
找到的版本10.9.1
操作系统Windows Server
操作系统版本2019 64 Bit
状态Non-Reproducible

附加信息

Query parameters should not be set by the user but defined by the relying party, which in this case is ArcGIS, so when configuring the ArcGIS openID configuration, query parameters should not be used when setting the logout URL. Query parameters for OpenID Connect logouts are limited to the predefined set documented in the OpenID Connect specification: https://openid.net/specs/openid-connect-rpinitiated-1_0.html#RPLogout The guide for configuring AWS Cognito on Github has been replaced since the previous one, published four years ago, was obsolete and contained an incorrect logout URL. https://github.com/Esri/idp/blob/main/Documentation/OpenID/AWS%20Cognito.md

重现步骤

漏洞 ID: BUG-000160730

软件:

  • Portal for ArcGIS

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项