Skip to content

Update dependency net.sf.jasperreports:jasperreports to v7 [SECURITY] (3.30) - #4054

Closed
renovate[bot] wants to merge 1 commit into
3.30from
renovate/3.30-maven-net.sf.jasperreports-jasperreports-vulnerability
Closed

Update dependency net.sf.jasperreports:jasperreports to v7 [SECURITY] (3.30)#4054
renovate[bot] wants to merge 1 commit into
3.30from
renovate/3.30-maven-net.sf.jasperreports-jasperreports-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Mar 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
net.sf.jasperreports:jasperreports (source) 6.20.67.0.4 age confidence

JasperReports has a Java deserialisation vulnerability

CVE-2025-10492 / GHSA-7c3f-cg9x-f3gr

More information

Details

A Java deserialisation vulnerability has been discovered in the Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library.

Severity

  • CVSS Score: 8.7 / 10 (High)
  • Vector String: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Release Notes

Jaspersoft/jasperreports (net.sf.jasperreports:jasperreports)

v7.0.4

Compare Source

v7.0.3

Compare Source

  • minor bug fixes and improvements;

v7.0.2

Compare Source

  • added support for horizontalPosition and shrinkWidth properties to table component and weight
    property to table columns to better control table resize behavior when table columns are hidden or resized.

  • removed the Google Maps component, the Chrome server side rendering of Javascript visualizations extension,
    the interactivity extension as well as the PL/SQL and Oracle stored procedure query executer;

  • various dependencies upgrades including: Apache Batik 1.18, Apache POI 5.3.0 and Spring 6.2.3;

  • minor bug fixes and improvements;

v7.0.1

Compare Source

  • added automatic module names to manifest files and fixed split packages issues in preparation for
    Java 9 modules compliance;

  • minor bug fixes and improvements;

v7.0.0

Compare Source

  • removal of the Ant build system and replacing it with a Maven build system;

  • deprecated code removed;

  • breaking backward compatibility of serialized/compiled *.jasper report template files,
    mostly because of historical deprecated serialization code removal/cleanup mentioned above
    (source *.jrxml report templates need to be recompiled to *.jasper using the new version of
    the library);

  • breaking backward compatibility of source *.jrxml report template files and *.jrtx style
    template files by replacing the Apache Commons Digester based parsers with Jackson XML object
    serialization. *.jrxml and *.jrtx files created with version 6 or older can no longer be loaded
    with version 7 or newer of the library alone. The conversion from the old file formats to the new
    file formats and back can be made using Jaspersoft Studio 7 and later versions of it;

  • extracting various optional extension JAR artifacts from the the core library JAR artifact
    to allow the Jakarta Migration of certain of these optional features while also introducing
    better third party Maven dependency management of these artifacts;

  • some Java package names have changed as a consequence of separating functionality into optional JAR artifacts;

  • upgraded JFreeChart to version 1.5.4 which no longer has support for 3D charts. Reports having
    Pie 3D, Bar 3D and Stacked Bar 3D charts would continue to work, but will be rendered as 2D,
    all their 3D effects being ignored;

  • minor bug fixes and improvements;

v6.21.5: JasperReports 6.21.5

Compare Source

  • added support for horizontalPosition and shrinkWidth properties to table component and weight
    property to table columns to better control table resize behavior when table columns are hidden or resized.

  • various dependencies upgrades including: Spring 6.2.3, Apache Batik 1.18,
    Apache Commons Codec 1.18.0, Apache Commons IO 2.18.0, Apache Commons Logging 1.3.5,
    Apache Log4J 2.24.3, Apache Commons Collections 4.5.0 and Apache POI 5.4.1;

  • minor bug fixes and improvements;

v6.21.4: JasperReports 6.21.4

Compare Source

  • various dependencies upgrades including: Jackson 2.17.1, RequireJS 2.3.7, Apache POI 5.3.0
    and Apache Xalan 2.7.3;

  • minor bug fixes and improvements;

v6.21.3

Compare Source

  • allow background section elements to be exported as page header content in the DOCX exporter
    so that watermark type effects could be achieved;

  • minor bug fixes and improvements;

v6.21.2

Compare Source

  • minor bug fixes and improvements;

v6.21.0

Compare Source

  • added support for PDF/A-2a, PDF/A-2b, PDF/A-2u, PDF/A-3a, PDF/A-3b, PDF/A-3u;

  • added support for WEBP images;

  • minor bug fixes and improvements;


Configuration

📅 Schedule: Branch creation - "" in timezone Europe/Zurich, Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the security Security fixes label Mar 5, 2026
@renovate
renovate Bot enabled auto-merge (squash) March 5, 2026 17:53
@sbrunner sbrunner closed this Mar 6, 2026
auto-merge was automatically disabled March 6, 2026 08:20

Pull request was closed

@sbrunner
sbrunner deleted the renovate/3.30-maven-net.sf.jasperreports-jasperreports-vulnerability branch March 6, 2026 08:21
@renovate

renovate Bot commented Mar 6, 2026

Copy link
Copy Markdown
Contributor Author

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update. You will not get PRs for any future 7.x releases. But if you manually upgrade to 7.x then Renovate will re-enable minor and patch updates automatically.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security Security fixes

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant