Skip to content
Discussion options

You must be logged in to vote

Hi @doogienz — you were right, and I am sorry this sat unanswered for two months.

Your report was accurate and the log you attached was exactly the evidence needed: the WAF printed IP blacklist loaded with a valid entry and then did not block. That was not a configuration mistake on your side. I investigated it properly today and it turned out to be three separate bugs, now published as GHSA-w6gv-76q4-prqg. You are credited as the reporter.

1. The IP blacklist never blocked anything, for anyone. loadIPBlacklist took the trie by value while both callers passed a dereferenced pointer, so every entry was inserted into a copy that was thrown away on return. The trie the WAF actually consults …

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by fabriziosalmi
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants