A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-1438.json"