AssertionConsumerServiceURL is a Java implementation for SAML Service Providers (org.keycloak.protocol.saml). Affected versions of this package are vulnerable to Cross-site Scripting (XSS).
AssertionConsumerServiceURL allows XSS when sending a crafted SAML XML request.
References:- https://github.com/keycloak/keycloak/security/advisories/GHSA-3p62-6fjh-3p5h
- https://github.com/keycloak/keycloak/commit/a1cfe6e24e5b34792699a00b8b4a8016a5929e3a
- https://nvd.nist.gov/vuln/detail/CVE-2022-4361
- https://bugzilla.redhat.com/show_bug.cgi?id=2151618
- https://github.com/advisories/GHSA-3p62-6fjh-3p5h