Keycloak: xss via assertion consumer service url in saml post-binding flow (CVE-2023-6717) | HOL Guard CVE