Description
Keycloak allows an unauthenticated attacker to send arbitrary values in 'request_uri' parameter and interact with internal network resources which is otherwise not accessible externally. An attacker may use this feature to perform Blind SSRF (Server-side request forgery) attacks on the server.
Remediation
Upgrade to the latest version of Keycloak
References
Related Vulnerabilities
WordPress Plugin Dropbox Folder Share Server-Side Request Forgery (1.9.7)
WordPress 4.7.x Multiple Vulnerabilities (4.7 - 4.7.14)
WordPress Plugin PhonePe Payment Solutions Server-Side Request Forgery (1.0.15)
Sitecore XP Deserialization RCE (CVE-2021-42237)
WordPress Plugin Flog Server-Side Request Forgery (1.0beta3)