A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter…
redhat·CWE-918·Published 2020-12-15