An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-2668.json"