RH-SSO 7.2 deployment in OpenShift 3.11 CORS not working

We’re having an issue where the CORS header disappears somewhere on the way from the backend service back to the browser when using Keycloak/RH-SSO 7.2. Without Keycloak/RH-SSO 7.2, the CORS header is there and things function as expected.

SSO_ENABLE_CORS is set to true in the environment of the deployment of RHSSO pod but it's not doing anything. Is there a bug??

Getting "No 'Access-Control-Allow-Origin' header is present on the requested resource."