Impact
Allows to bypass the WAF when a malicious X-Forwarded-For
IP matches IgnoreIP
IgnoreCIDR
rules.
This old code was arranged to allow older NGINX versions to also support IgnoreIP
IgnoreCIDR
when multiple reverse proxies were present.
Patches
Patched in 1b71252
Workarounds
Do not set any IgnoreIP
IgnoreCIDR
for older versions.
References
#103
Impact
Allows to bypass the WAF when a malicious
X-Forwarded-For
IP matchesIgnoreIP
IgnoreCIDR
rules.This old code was arranged to allow older NGINX versions to also support
IgnoreIP
IgnoreCIDR
when multiple reverse proxies were present.Patches
Patched in 1b71252
Workarounds
Do not set any
IgnoreIP
IgnoreCIDR
for older versions.References
#103