4.4.11 Ensure 'logoutPageRedirectDomainNames' is set to valid host names to redirect after logout

Information

Once a user is logged out, the logout page redirects can be controlled to be redirected to a specific set of trusted domains instead of just localhost.

One can control the domain names to be directed to once a logout happens. This will ensure that the redirection is not happening to an untrusted server.

Solution

Add/set the setting below to ${server.config.dir}/configDropins/overrides/<any file name>.xml

<webAppSecurity logoutPageRedirectDomainNames="<domain name list>" />

See Also

https://workbench.cisecurity.org/benchmarks/7724

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-12

Plugin: Unix

Control ID: e3575f4d21289f03d527169914cbd1b921e5f30e3d436cb803409544929a2d71