Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
[ { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/filesdiagram/FilesListing.java" }, "digest": { "line_hashes": [ "37751915871913835672112786978192838122", "23372530611755373878532809410721831971", "174350955963885678873323407022859766529", "269924227392708133734500043100717541246", "45856211166980502706953821296970934447", "59447078204574086070376768539577689765", "169701850415912233543654035962200863926", "154909191808420019582339877228104844410", "55968946465262011321446641440710119828", "81461673642830719704862775468488386471", "338456228005936216879461405605532106908", "219324995357183732967408381129357096413", "116023290169119605292888659166280399354", "65503437511565457568366429565632441799", "174397779130780454070605642014161502701", "28501851026464892009670720094263155396", "212428700789193639483588839061372696604", "6282746983053536747749875499374394650", "328061022831982089216062718159930346168", "94780160881751023074654589289858977456", "47124917132728315574206370269607328043", "172920339976631594137151014737511086209", "76187102641193831069511473598757010134", "132779034768289625198247761443564348736", "164200510999156979169020017933045081645", "26201043652260817300548335847711608295", "138585791315989948481332253636330213000", "223771092705152809196791857591772312906", "110314325304903055647320057347695601748", "76067828204369968854934325635906451105" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-028668c5", "signature_type": "Line" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "fileCandidates", "file": "src/net/sourceforge/plantuml/version/LicenseInfo.java" }, "digest": { "function_hash": "260978468242442531509101220553946110292", "length": 430.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-0b8de2ca", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/nwdiag/core/NServer.java" }, "digest": { "line_hashes": [ "250184420805281362177344728103395030165", "212199448113344148508026108220448752570", "78131748571832327943488356418930303028", "232922089688138115221622047917485681065" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-1090342f", "signature_type": "Line" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "setIfValid", "file": "src/net/sourceforge/plantuml/version/LicenseInfo.java" }, "digest": { "function_hash": "339043294609269330458131896717501648033", "length": 134.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-1685ed7a", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/nwdiag/NwDiagram.java" }, "digest": { "line_hashes": [ "11994359659978096913518506910935584901", "258587082312529767275267691325924623739", "106439634381247215971171835840309094873", "311717170847973573031252984097636727668", "189660044230228180759283883256778008552", "246246434986475207233855198589288457184", "335012301499771668657023393216233063388", "273741954206696519091906799920147690058" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-257f5315", "signature_type": "Line" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/file/AParentFolderRegular.java" }, "digest": { "line_hashes": [ "30394080576069426460831315213718700844", "300564765945036727923329888329552668554", "13800351095389164096949615878116918427", "3581662522053690898480913170359603081", "290608306423643891845555130900011369268", "250372717486844781647271382630136695622", "177477990457682191620769600581990006424", "278342446585691734632908766196495567892", "72747681316045424685413465082643740528", "336348336129689144962180271666270731957", "67285741456772442012070940876174401461" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-33e151bf", "signature_type": "Line" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "openNetwork", "file": "src/net/sourceforge/plantuml/nwdiag/NwDiagram.java" }, "digest": { "function_hash": "153358449141603418358046295796616242957", "length": 386.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-367cab4d", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/security/SURL.java" }, "digest": { "line_hashes": [ "143333218455567301628571406478352178790", "109491466123470802612051215714335675931", "5842884138653126568086148841893951778", "196700123157187376196463142643623451299", "298263046011580523654429837297514098380", "215448818219793769249604620224543732677", "236684581495582866498493360007052919455", "46462064134495245130701938936254962906", "26742986795148829985559106072199889075", "27149983159558346646325790287991373313", "195405909041224442860522250221956988388", "272172008371666951144992344992735772049" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-4be40b4e", "signature_type": "Line" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/version/Version.java" }, "digest": { "line_hashes": [ "57689475120811609999595027420428185483", "126759652758404580841147787734850968583", "230457914003975769188183035425237151591", "59820292453356263270386254593600456982" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-6d0099b6", "signature_type": "Line" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "setGray", "file": "src/net/sourceforge/plantuml/klimt/sprite/SpriteColor.java" }, "digest": { "function_hash": "33081104906756236730131842722178978980", "length": 289.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-720bf0cd", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "drawU", "file": "src/net/sourceforge/plantuml/filesdiagram/FilesListing.java" }, "digest": { "function_hash": "49970528943647832458334094736879561608", "length": 348.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-791a505a", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "retrieveNamedSlow", "file": "src/net/sourceforge/plantuml/version/LicenseInfo.java" }, "digest": { "function_hash": "55008276479410684876365584598011059336", "length": 615.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-7ab9fc41", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "toUImage", "file": "src/net/sourceforge/plantuml/klimt/sprite/SpriteColor.java" }, "digest": { "function_hash": "107299213203153650089063613279508324", "length": 771.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-81833fd7", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "line_hashes": [ "39970575624222174054003873345579481885", "181567803699607454483335027831181783410", "288124371335665219718047096596300872257", "131225207581727714118197481177634035398", "139742519864166402766633268337345427928", "278414941179270871761611426727497725899", "157562596629229217874020234498917340011", "321608048266135367654019602014523915248", "200491851455120475970132234841781726773", "157991096924353395793436189740821784776", "329085925469799431375985570824078542775", "114234943347625192062834149295860083853", "160549978468118857630303363020433199488", "176414884163057952864506301064611504244", "303116080559188174842896068316793620468", "157966570835004369218096977383168330087", "218115797911054755546457913331359498836", "16905339941569016436879368237932830114", "71138696199744711607594040946381918002", "34309926388375393417766286561948690990", "241683619567853569169863298720709241167", "217893874226193766556048510958638895120", "62277115982629535890332778486155030927", "252180484750157756346078250294222255413", "119657645768422278488022934526712878337", "200470888323075963400121249438039641880", "2441945825693785867777776814642670153", "187970893628927618306658283881897019917", "317823417040192103987602396704424756731", "320999296732354213328406005526655273546", "254590882538033028786277005343423638838", "175342994347744763903787244626303612444", "284561479981330636785974522421544509090", "267259017609100355527314236562966820013", "21106938180822171868577694205946820279", "184267805749606301102664804474259417041", "166214739422004334870864647018414814405", "277621832287639752226699292566293308744", "175656901765246629718313926122235573683", "104824718181219250708100555594897611657", "148291210846631421972613658807885627403", "5027456766134282598193910140884556270", "80579424437075562433263550416046777911", "77953170285976793976520090486730010623", "211099201475335189231871529965315494515", "138088403928176843384937178914601324813", "226988888367914825664937663316673491067", "138592765209344903958488182805517911277", "334962257080178569216411240006275601466", "80356620543493079097562562698237116446", "335249281768823607657654262182785722437", "282323096599774988152419079031223530403", "145436120891486252361667624254131187503", "300196134054691607975935517913562372517", "136748608752077289169245189971186737053", "183876812467327379592288412859697585898", "117694893828769809790409952407551200695", "260067739210365574251164838709483904102", "338765423172973708779328747592569985", "125435592433955714922135548047779954382", "229350161257657092743740705715720187095", "289358437513103882805520712028980584923", "16083988430143768725298816881932080634", "63579125030791346589195973106730677631", "254705617008664870516616884529487796480", "191048660345779278010488587588690436017", "223824581570980264770682847352443060020", "118743772816147738535678598582480555480", "169886253008519338988408624219605932157", "29137278580501833741176868624877014717", "262047950751737540858114532923641486399", "133495204909877522781153568106932781633", "312557662001712871028534489513401510862", "187870917408358827913117359481289725274", "214519990465479330630093119365127356481", "47148411467043056711109571271419916162", "230077674327345685919556340171809672762", "52492597435111683684301159491427565935", "29919402536082400689793177151052403030", "218860774695592801859490120383341042799", "198748648541965509043454520334744191364", "324321525007456364577984401221711328811", "244349463371536531115769353872580302397" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-86bbc836", "signature_type": "Line" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/version/LicenseInfo.java" }, "digest": { "line_hashes": [ "171321002373993746744092519034823748202", "32832941284820613979638798643977314410", "181485114183600814848851509141726494170", "172838935519035620404790517542970904944", "101027240316867395004054102899008695652", "135164976804450869356401800487519732127", "277830853618333874222247054523867362663", "328740571661926934401423461855205289363", "285193033780857180782995515076030435249", "242387448497645623517487165041063455621", "331545284109319217125960949971547946312", "295032716505435689556692400604658003627", "307995615175629837411989856469091112858", "212872460405840689434733799561379317351", "81411137406145350785032613482720018271", "53161247868503390482389335152936569028", "10653495153153935109668883341328059239", "11162592193432135730963283423547239033", "22870936339471794779109430306980240828", "232332463746087016308992308472214199243", "192132163535674868612095565837877885806", "242387448497645623517487165041063455621", "9055133332014897482443224774669799264", "292472146533983485423728708512489191627", "325058905094549027070953749807635051542", "15540521998923873945997841971159037632", "59009792174546641748787116176008014225", "318156378579668922120219393701999735990", "276707495790419481909968949393858823025", "108691011720936626333987339065847564551", "256501122206509977384097009034070462928", "67072456922940190475272391032915799351", "55300160800378202868174435821472037540", "229186232766724308751635443922658091719", "141995730934972767601047061943178164144", "49910011953859255377773686527300573685", "282625478297600304456841954107966709503", "67072456922940190475272391032915799351", "326023328466803042465820320724501153624", "86072440267743870532868003040638359263", "11803800496141843947474232976209871421", "173178184363544605509957284643775948090", "96954836143273749704418637088881683074", "119322412006079366224663991988277797079", "299143512661401826118219536225402382433", "227239449262578764895446981460494157191", "15819683230594361177116686680027152065", "336079503267226359852143712007949831330", "124160899413460227771804190842021120754", "337495676800810748937736356921653370937", "172733258323874924450862402506271957721", "95820431009378322434153420337530951945", "257581844378240777781293681312672731232", "83835112858178527554906493118370127854", "135415089523999643482142229287236300253", "222652961926901239074859646140693783684", "191030403299871298014566886997312975349", "107645569212768440086987886124603077094", "215705422585741694920514421774083980041", "27676482128873363671670759480758106662", "148129437478951903155948616559662285372", "319952333825717071274842693503516949989", "9298351508957061668177957991538452506", "149027759752905983211699019702174211502", "151515977663779299309250978338456584060", "43512454968830758359268510979945232894", "223885416106445709345824259562070833161", "151797020345215870045131401046860754808", "107244084649580121020248585078687779025", "3929400452559481053298332264085746347", "234837350799268735194901625074993058421", "338001568677495785447139771023965294881", "80072945508345426569303086361036646663", "174895700648424366012985719162343194663", "74962725995481519492357880823783388200", "202064464271930174924836065560624335369", "232356475737933555971371665384202258580" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-8c7f0611", "signature_type": "Line" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "executeReturnFunction", "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "function_hash": "250040350020858970224923181696577457955", "length": 676.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-8cb8d5da", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "retrieveDistributor", "file": "src/net/sourceforge/plantuml/version/LicenseInfo.java" }, "digest": { "function_hash": "117473346495049367694931626145878765733", "length": 551.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-961b1dce", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "finalizeEnddefinelong", "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "function_hash": "235065840459590495149209298857559800720", "length": 263.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-9e96bb51", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "isInUrlAllowList", "file": "src/net/sourceforge/plantuml/security/SURL.java" }, "digest": { "function_hash": "157845343852631871878361263827131967280", "length": 188.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-a1460975", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "retrieve", "file": "src/net/sourceforge/plantuml/version/LicenseInfo.java" }, "digest": { "function_hash": "212847280340323019861559550984103674348", "length": 352.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-a14e0d18", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "add", "file": "src/net/sourceforge/plantuml/filesdiagram/FilesListing.java" }, "digest": { "function_hash": "296555523669376913114141769349798931545", "length": 110.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-a9d215f8", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "learnThisAddress", "file": "src/net/sourceforge/plantuml/nwdiag/core/NServer.java" }, "digest": { "function_hash": "258886403375711120601108660276290161253", "length": 200.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-b3b344f6", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "canCover", "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "function_hash": "138071028229889328889092506346773751953", "length": 473.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-c8c2647d", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "executeProcedureInternal", "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "function_hash": "199264321538968100990868836397720826664", "length": 378.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-cf68f1b1", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "getNewMemory", "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "function_hash": "299254232378875963514030180365913535768", "length": 527.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-d4b9d25d", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "executeReturnLegacyDefine", "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "function_hash": "338458212699969724047737978902314077173", "length": 439.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-d5c9ab5a", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "addBody", "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "function_hash": "18419400358563102954695781867237756264", "length": 362.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-d6f28a28", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "forbiddenURL", "file": "src/net/sourceforge/plantuml/security/SURL.java" }, "digest": { "function_hash": "283894174338721677850484930234443949692", "length": 353.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-e0b4c84c", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "retrieveDistributorImage", "file": "src/net/sourceforge/plantuml/version/LicenseInfo.java" }, "digest": { "function_hash": "119026376407191890091959442699337681126", "length": 562.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-e42447c6", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "getAFile", "file": "src/net/sourceforge/plantuml/file/AParentFolderRegular.java" }, "digest": { "function_hash": "13852513156929939782133320628705159057", "length": 268.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-e7c6bd01", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "TFunctionImpl", "file": "src/net/sourceforge/plantuml/tim/TFunctionImpl.java" }, "digest": { "function_hash": "239560329519990481176067891521858560389", "length": 322.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-e9a7c083", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "function": "setColor", "file": "src/net/sourceforge/plantuml/klimt/sprite/SpriteColor.java" }, "digest": { "function_hash": "191493999899890404335283491718885612267", "length": 228.0 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-f64131d8", "signature_type": "Function" }, { "source": "https://github.com/plantuml/plantuml/commit/b32500bb61ae617bb312496d6d832e4be8190797", "target": { "file": "src/net/sourceforge/plantuml/klimt/sprite/SpriteColor.java" }, "digest": { "line_hashes": [ "226533321103460629468983636685820450477", "212698007892865600594946978983137824881", "6497499532337168571736518373501518256", "253165346451906432542616267485735632982", "234169306236514631026768499654833177465", "172305323925242718525707231452043176512", "194064423599382269959205047249352482943", "239886274743399149710714763441474812697", "136510493635856706185306659866617373588", "158433945304009720318454048870027314456", "325137051040958170123912691951430429727", "215012520854256139519020967309131080527", "20233307590165431621131591611830922117", "95609629397131288342443257771037981950", "279178966005479696301145387302879521335", "88250277689980226718151705388496392014", "253165346451906432542616267485735632982", "234169306236514631026768499654833177465", "172305323925242718525707231452043176512", "264014366442328549613200306928061172612", "79413173386474436082088924967397045657", "207878791533024318644750999828570939010", "286405303602402994911302078551590684181", "330930292911412462866981405418759086866", "287470425911786395933224070191316990220", "336667151781015707101544102667829547531", "261222656681122532180270880931776246759", "243201043910859500277110849016402514281", "58232677658065825962471488529962547543", "87784138384905911189408934079424371610", "249209897398786239043107434992226882111", "90010744141466937963659072518548510660" ], "threshold": 0.9 }, "deprecated": false, "signature_version": "v1", "id": "CVE-2023-3432-f77f8d71", "signature_type": "Line" } ]