oscerd opened a new pull request, #27180:
URL: https://github.com/apache/camel/pull/27180

   Backport of #27118 (CAMEL-25162) to `camel-4.18.x`.
   
   Straight cherry-pick of the merged squash commit `5326d407` — the code patch 
is byte-identical to the
   original (verified). The vulnerable `OAuthCodeFlowProcessor.getPostLoginUrl` 
reconstruction from
   caller-controlled `X-Forwarded-*` / `Host` headers is present on 4.18.x, so 
the open-redirect applies
   here too; the fix confines the post-login URL to the origin of the 
configured `camel.oauth.redirect-uri`
   and carries over only the request path.
   
   The upgrade-guide note lives on `main` only (project policy), so it is not 
part of this backport.
   
   `mvn clean test -pl components/camel-oauth` on camel-4.18.x: **140 run, 0 
failures, 0 errors, 7 skipped**
   (the skips are the pre-existing Testcontainers ITs).
   
   🤖 Generated with [Claude Code](https://claude.com/claude-code)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to