Keycloak 12.0.1 and below allows an attacker to force the server to request an unverified URL using the OIDC parameter request_uri. This allows an attacker to execute a server-side request forgery (SSRF) attack.
View the template here CVE-2020-10770.yaml
References:
https://www.exploit-db.com/exploits/50405