Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri
Details
Keycloak prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This could permit an attacker to submit a specially crafted request leading to XSS or possibly further attacks.