{"id":"CVE-2023-45132","summary":"IgnoreIP/IgnoreCIDR should not trust X-Forwarded-For","details":"NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 and prior to version 1.6 allows someone to bypass the WAF when a malicious `X-Forwarded-For` IP matches `IgnoreIP` `IgnoreCIDR` rules. This old code was arranged to allow older NGINX versions to also support `IgnoreIP` `IgnoreCIDR` when multiple reverse proxies were present. The issue is patched in version 1.6. As a workaround, do not set any `IgnoreIP` `IgnoreCIDR` for older versions.\n","aliases":["GHSA-7qjc-q4j9-pc8x"],"modified":"2026-08-12T14:51:17.061891Z","published":"2023-10-11T20:21:26.313Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-693"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45132.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/45xxx/CVE-2023-45132.json"},{"type":"ADVISORY","url":"https://github.com/wargio/naxsi/security/advisories/GHSA-7qjc-q4j9-pc8x"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-45132"},{"type":"FIX","url":"https://github.com/wargio/naxsi/commit/1b712526ed3314dd6be7e8b0259eabda63c19537"},{"type":"FIX","url":"https://github.com/wargio/naxsi/pull/103"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wargio/naxsi","events":[{"introduced":"b77c17261aba04e749a5072b96f97294bf830149"},{"fixed":"f74611640b76a798cdedcc3fa1147b69eaac969f"},{"fixed":"1b712526ed3314dd6be7e8b0259eabda63c19537"}],"database_specific":{"cpe":"cpe:2.3:a:wargio:naxsi:*:*:*:*:*:nginx:*:*","extracted_events":[{"introduced":"1.3"},{"fixed":"1.6"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["1.5rc1","1.5","1.4","1.4rc1","1.3"],"database_specific":{"vanir_signatures":[{"source":"https://github.com/wargio/naxsi/commit/1b712526ed3314dd6be7e8b0259eabda63c19537","target":{"file":"naxsi_src/naxsi_runtime.c","function":"ngx_http_naxsi_update_current_ctx_status"},"deprecated":false,"digest":{"function_hash":"193056712333726188793878323090297118995","length":3349},"id":"CVE-2023-45132-192683b6","signature_type":"Function","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/wargio/naxsi/commit/1b712526ed3314dd6be7e8b0259eabda63c19537","target":{"file":"naxsi_src/naxsi_runtime.c"},"deprecated":false,"digest":{"line_hashes":["255600741669479245157628770692233025452","131493001970561476635954717180140332991","235606413654588176032928585183968391399","8479830720874287821181550880475154675","249288007779799812459386056378005576641","134680205279150047203834891308556440658","25727489045417606664521658473324512831","122657220096542184666162752293462592047","55039191419325605346197707506647620020","142056471848753636442027371345348852872","328441335327633939871749982705996245015","297376535739547836259434844202493093277","150456247649496043352466643884710135792","328246844819090227924657188152084124992","69570658552730641228321497262304494311","276711224409397226724955495152795890684","84888832592924176610551950259676422556","285297503150886787700831303345894385804","266744356598504722409259541721480334139","12731702012750881685412539010336858107","275121843106356069518426712159506076857","55039191419325605346197707506647620020","142056471848753636442027371345348852872","99058730499071222509685510854244788970","184562197946195231056123137320161006779","205902995771934882689692390647431082110","198111895681457841323754331642616254931","10808363965216511259485418777365594767","101577848387913402175890467837459198229","255624748720564269270970125138023137156","54277282129907038978647650242916450700","235332503247728102296771147468096348887","219367371171432307948158618069559387454","33475580191689230824579844540270012136","111502526315165590925939579849576963322","151123672977893038350397704555652694532","151050795785611588804443246826641370875"],"threshold":0.9},"id":"CVE-2023-45132-784c3adc"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-45132.json","vanir_signatures_modified":"2026-08-12T14:51:17Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}