I'm 100% on your side regarding the XSS issue but you can't expect them to have a list of security vulnerabilities that they've already discovered at your disposal.
Also: this is Uber. At this point, they’ve used up all their good faith. I definitely wouldn’t be taking anything they say in good faith - I still haven’t forgotten them threatening a journalist or publicly tracking the ride of a CEO for an entire room of people!
SAML has an actual logout endpoint
I think there is more to this story, it sounds like this wasn't a "Cross Site Scripting", but "Content Injection" or "Content Spoofing", a far less serious bug.
You're gonna hate me, but I would award $0 for Content Injection, it's just not a big deal ¯\_(ツ)_/¯
The second POC demonstrated the ability to evade both their WAF and XSS_Auditor.
Their development team then verified the ability to execute arbitrary JavaScript from any *.cloudfront.net host.
That's pretty much the whole story.
If you couldn't, it's plausible the non-security developers incorrectly speculated it was possible?
That's false. Non-expired authentication tokens is a serious issue.