Comment 50 for bug 1409142

Revision history for this message
Tristan Cacqueray (tristan-cacqueray) wrote : Re: Websocket Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259)

Thanks alaski for the quick guidance!
In order to not force a new requirement, we can try to load that configuration and use it when possible... Then we can amend the OSSA with a note saying that the websocketproxy server needs access to nova.conf in order to have full protection...

And just to be sure, xvpvncproxy_base_url and html5proxy_base_url are out of scope here right ?