Skip to content
Open
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next Next commit
chore: Upgrade to JasperStarter 3.6.2
  • Loading branch information
Xint0-elab committed Feb 21, 2022
commit e466e5bdc09987a21a55bbb38656f31392400a04
5 changes: 5 additions & 0 deletions bin/jasperstarter/.gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
CHANGES text eol=crlf
LICENSE text eol=crlf
NOTICE text eol=crlf
README.md text eol=crlf
jdbc/README text eol=crlf
37 changes: 36 additions & 1 deletion bin/jasperstarter/CHANGES
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,41 @@
JasperStarter - Running JasperReports from command line
========================================================

Release notes - JasperStarter - Version 3.6.2
---------------------------------------------

** Bug
* JAS-161 CVE-2021-44832 in log4j-2.17.0


Release notes - JasperStarter - Version 3.6.1
---------------------------------------------

** Bug
* JAS-160 log4j 2.16.0 is vulnerable to CVE-2021-45105


Release notes - JasperStarter - Version 3.6.0
---------------------------------------------

** Bug
* CVE-2019-17571 - Included in Log4j 1.2 is a SocketServer class that is
vulnerable to deserialization of untrusted data which can be exploited to
remotely execute arbitrary code when combined with a deserialization
gadget when listening to untrusted network traffic for log data. This
affects Log4j versions up to 1.2 up to 1.2.17.

* [JAS-158] Jasperstarter contains an old log4j-1.2.17 which is affected by CVE-2019-17571
* [JAS-146] mvn: Could not resolve dependencies \(...\) from/to jaspersoft.artifactoryonline.com
* [JAS-142] Failed to generate qrcode - zxing library missing

** Improvement
* [JAS-156] Is JasperStarter vulnerable to CVE-2021-44228

** Task
* [JAS-157] Include JasperReports 6.18.1


Release notes - JasperStarter - Version 3.5.0
---------------------------------------------

Expand Down Expand Up @@ -359,7 +394,7 @@ JasperStarter is now able to prompt for report parameters.
jrxml - compiles implicit
jrprint - print, view or export previously filled reports.
New output type: jrprint. This makes --keep obsolete.
New parameter -w writes compiled file to imput dir if jrxml is
New parameter -w writes compiled file to input dir if jrxml is
processed.
Parameter -t defaults to "none" and can therefore be omited if no
database is needed.
Expand Down
Empty file modified bin/jasperstarter/LICENSE
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/NOTICE
100755 → 100644
Empty file.
10 changes: 8 additions & 2 deletions bin/jasperstarter/README.md
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,12 @@ JasperStarter is an opensource command line launcher and batch compiler for

The official homepage is [jasperstater.cenote.de][].

**JasperStarter is not vulnerable to [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228).**

**But all releases including 3.5.0 contain log4j-1.2.17 which is affected by
[CVE-2019-17571](https://nvd.nist.gov/vuln/detail/CVE-2019-17571).** I cannot say if it is possible to
exploit this with JasperStarter but in any case you should update to a newer version of JasperStarter.

It has the following features:

* Run any JasperReport that needs a jdbc, csv, xml, json, jsonql or empty datasource
Expand All @@ -33,7 +39,7 @@ It has the following features:

Requirements:

* Java 1.8 or higher
* Java 1.8
* A JDBC 2.1 driver for your database


Expand Down Expand Up @@ -228,4 +234,4 @@ limitations under the License.
[Usage]:http://jasperstarter.sourceforge.net/usage.html
[Issues]:https://cenote-issues.atlassian.net/browse/JAS
[Changes]:changes.html
[jpy]:https://github.com/bcdev/jpy
[jpy]:https://github.com/bcdev/jpy
2 changes: 1 addition & 1 deletion bin/jasperstarter/bin/jasperstarter
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
if(test -L "$0") then
auxlink=`ls -l "$0" | sed 's/^[^>]*-> //g'`
HOME_FOLDER=`dirname "$auxlink"`/..
else
else
HOME_FOLDER=`dirname "$0"`/..
fi

Expand Down
Binary file modified bin/jasperstarter/bin/jasperstarter.exe
Binary file not shown.
Empty file modified bin/jasperstarter/lib/ant-1.7.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/ant-launcher-1.7.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/antlr-2.7.7.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/antlr-3.0b5.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/argparse4j-0.5.0.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/avalon-framework-impl-4.2.0.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/barbecue-1.5-beta1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/barcode4j-2.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-anim-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-awt-util-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-bridge-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-constants-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-css-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-dom-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-ext-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-gvt-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-i18n-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-parser-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-script-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-svg-dom-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-svggen-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-util-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-xml-1.9.1.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/bcprov-jdk15on-1.52.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/bcprov-jdk15on-1.68.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/castor-core-1.3.3.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/castor-core-1.4.1.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/castor-xml-1.3.3.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/castor-xml-1.4.1.jar
Binary file not shown.
Binary file not shown.
Empty file modified bin/jasperstarter/lib/commons-cli-1.0.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/commons-codec-1.10.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/commons-collections-3.2.2.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/commons-collections4-4.1.jar
Binary file not shown.
Binary file not shown.
Empty file modified bin/jasperstarter/lib/commons-digester-2.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/commons-io-2.5.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/commons-lang-2.6.jar
100755 → 100644
Empty file.
Binary file added bin/jasperstarter/lib/commons-lang3-3.4.jar
Binary file not shown.
Empty file modified bin/jasperstarter/lib/commons-logging-1.1.1.jar
100755 → 100644
Empty file.
Binary file added bin/jasperstarter/lib/core-2.3.0.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/ecj-3.21.0.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/ecj-4.4.2.jar
Binary file not shown.
Empty file modified bin/jasperstarter/lib/groovy-all-2.4.12.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/icu4j-57.1.jar
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file removed bin/jasperstarter/lib/jackson-annotations-2.9.5.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/jackson-core-2.12.2.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/jackson-core-2.9.5.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/jackson-databind-2.12.2.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/jackson-databind-2.9.5.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/jasperreports-6.18.1.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/jasperreports-6.7.0.jar
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file modified bin/jasperstarter/lib/jasperstarter.jar
100755 → 100644
Binary file not shown.
Empty file modified bin/jasperstarter/lib/javax.inject-1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/jcalendar-1.4.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/jcommon-1.0.23.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/jfreechart-1.0.19.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/joda-time-2.9.9.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/jython-2.7.0.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/log4j-1.2.17.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/log4j-api-2.17.1.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/log4j-core-2.17.1.jar
Binary file not shown.
Empty file modified bin/jasperstarter/lib/poi-3.17.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/rhino-1.7.7.2.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/serializer-2.7.2.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/servlet-api-2.5.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/spring-beans-4.3.21.RELEASE.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/spring-core-4.3.21.RELEASE.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/spring-expression-4.3.21.RELEASE.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/stax-1.2.0.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/stax-api-1.0-2.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/stax-api-1.0.1.jar
Binary file not shown.
Empty file modified bin/jasperstarter/lib/stringtemplate-3.0.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/xalan-2.7.2.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/xml-apis-1.3.04.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/xml-apis-ext-1.3.04.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/xmlgraphics-commons-2.2.jar
100755 → 100644
Empty file.