Comment 73 for bug 1409142

Revision history for this message
Andrew Laski (alaski) wrote : Re: Websocket Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259)

In general the answer seems to be no. https://wiki.openstack.org/wiki/StableBranch#Appropriate_Fixes

If the vulnerability was of a severe enough nature and that was the only way to address it we could work out a way to do it, but for this I think you'll need to go with a config parameter.