oscerd opened a new pull request, #27180: URL: https://github.com/apache/camel/pull/27180
Backport of #27118 (CAMEL-25162) to `camel-4.18.x`. Straight cherry-pick of the merged squash commit `5326d407` — the code patch is byte-identical to the original (verified). The vulnerable `OAuthCodeFlowProcessor.getPostLoginUrl` reconstruction from caller-controlled `X-Forwarded-*` / `Host` headers is present on 4.18.x, so the open-redirect applies here too; the fix confines the post-login URL to the origin of the configured `camel.oauth.redirect-uri` and carries over only the request path. The upgrade-guide note lives on `main` only (project policy), so it is not part of this backport. `mvn clean test -pl components/camel-oauth` on camel-4.18.x: **140 run, 0 failures, 0 errors, 7 skipped** (the skips are the pre-existing Testcontainers ITs). 🤖 Generated with [Claude Code](https://claude.com/claude-code) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
