Description
An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
Remediation
References
https://access.redhat.com/security/cve/CVE-2022-2668
Related Vulnerabilities
CVE-2023-27025 Vulnerability in maven package com.ruoyi:ruoyi-quartz
CVE-2023-49620 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-common
CVE-2022-25167 Vulnerability in maven package org.apache.flume:flume-parent
CVE-2020-8913 Vulnerability in maven package com.google.android.play:core
CVE-2022-36272 Vulnerability in maven package net.mingsoft:ms-mcms