从这个网页截图中,可以获取到以下关于漏洞的关键信息: 1. 漏洞编号:RHSA-2024:69 2. 发布日期:2024-09-09 3. 类型/严重性:Security Advisory, Moderate 4. 主题:New Red Hat build of Keycloak 24.0.7 packages are available from the Customer Portal 5. 描述: - Red Hat build of Keycloak 24.0.7 is a standalone server, based on the Keycloak project, that provides authentication and standards-based single sign-on capabilities for web and mobile applications. - Security fixes: - session fixation in elytron saml adapters (CVE-2024-7341) - One Time Passcode (OTP) is valid longer than expiration time (CVE-2024-7318) - Open Redirect on Account page (CVE-2024-7260) 6. 解决方案: - Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on. 7. 受影响的产品: - Red Hat build of Keycloak 22 x86_64 8. 修复: - BZ - 2301875 - CVE-2024-7260 keycloak-core: Open Redirect on Account page - BZ - 2301876 - CVE-2024-7318 keycloak-core: One Time Passcode (OTP) is valid longer than expiration time - BZ - 2302064 - CVE-2024-7341 wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters 9. CVEs: - CVE-2024-7260 - CVE-2024-7318 - CVE-2024-7341 10. 参考链接: - https://access.redhat.com/security/updates/classification/#moderate 这些信息提供了关于漏洞的详细描述、修复措施和受影响的产品等关键信息。