Security Advisory
CVE-2022-2668
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled