Comment 104 for bug 1409142

Revision history for this message
Paul McMillan (paul-mcmillan) wrote : Re: Websocket Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259)

@Thomas: As Tristan said, and as I have reiterated multiple times on the debian bug, the issue with novnc is separate from this one. I've added you to this bug https://bugs.launchpad.net/nova/+bug/1420942 which tracked that separate, independent bug (it is a bug in novnc, it is not a nova bug, and not an openstack bug, but still private until we can get the OSSN sent out).

Thank you for proposing the fix for noVNC into Debian, it will be easier to work upstream from there.