Description
An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
Remediation
References
https://access.redhat.com/security/cve/CVE-2022-2668
Related Vulnerabilities
CVE-2023-30857 Vulnerability in npm package @aedart/support
CVE-2022-45401 Vulnerability in maven package org.jenkinsci.plugins:associated-files
CVE-2023-31103 Vulnerability in maven package org.apache.inlong:manager-test
CVE-2018-3751 Vulnerability in npm package merge-recursive
CVE-2021-1628 Vulnerability in maven package org.mule.runtime:mule-core