Comment 92 for bug 1409142

Revision history for this message
Andrew Laski (alaski) wrote : Re: Websocket Hijacking Vulnerability in Nova VNC Server (CVE-2015-0259)

I have one concern with the patches. It requires https if either base url uses https. So a legitimate http novnc request could be failed if the spice base url uses https. I think this needs to go the other way and require that the protocol matches or exceeds the lesser of the protocols where http < https.