Skip to content

Commit

Permalink
chore: Upgrade to JasperStarter 3.6.2
Browse files Browse the repository at this point in the history
  • Loading branch information
Xint0-elab committed Feb 21, 2022
1 parent 3939a11 commit 57ae498
Show file tree
Hide file tree
Showing 93 changed files with 50 additions and 4 deletions.
5 changes: 5 additions & 0 deletions bin/jasperstarter/.gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
CHANGES text eol=crlf
LICENSE text eol=crlf
NOTICE text eol=crlf
README.md text eol=crlf
jdbc/README text eol=crlf
37 changes: 36 additions & 1 deletion bin/jasperstarter/CHANGES
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,41 @@
JasperStarter - Running JasperReports from command line
========================================================

Release notes - JasperStarter - Version 3.6.2
---------------------------------------------

** Bug
* JAS-161 CVE-2021-44832 in log4j-2.17.0


Release notes - JasperStarter - Version 3.6.1
---------------------------------------------

** Bug
* JAS-160 log4j 2.16.0 is vulnerable to CVE-2021-45105


Release notes - JasperStarter - Version 3.6.0
---------------------------------------------

** Bug
* CVE-2019-17571 - Included in Log4j 1.2 is a SocketServer class that is
vulnerable to deserialization of untrusted data which can be exploited to
remotely execute arbitrary code when combined with a deserialization
gadget when listening to untrusted network traffic for log data. This
affects Log4j versions up to 1.2 up to 1.2.17.

* [JAS-158] Jasperstarter contains an old log4j-1.2.17 which is affected by CVE-2019-17571
* [JAS-146] mvn: Could not resolve dependencies \(...\) from/to jaspersoft.artifactoryonline.com
* [JAS-142] Failed to generate qrcode - zxing library missing

** Improvement
* [JAS-156] Is JasperStarter vulnerable to CVE-2021-44228

** Task
* [JAS-157] Include JasperReports 6.18.1


Release notes - JasperStarter - Version 3.5.0
---------------------------------------------

Expand Down Expand Up @@ -359,7 +394,7 @@ JasperStarter is now able to prompt for report parameters.
jrxml - compiles implicit
jrprint - print, view or export previously filled reports.
New output type: jrprint. This makes --keep obsolete.
New parameter -w writes compiled file to imput dir if jrxml is
New parameter -w writes compiled file to input dir if jrxml is
processed.
Parameter -t defaults to "none" and can therefore be omited if no
database is needed.
Expand Down
Empty file modified bin/jasperstarter/LICENSE
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/NOTICE
100755 → 100644
Empty file.
10 changes: 8 additions & 2 deletions bin/jasperstarter/README.md
100755 → 100644
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,12 @@ JasperStarter is an opensource command line launcher and batch compiler for

The official homepage is [jasperstater.cenote.de][].

**JasperStarter is not vulnerable to [CVE-2021-44228](https://nvd.nist.gov/vuln/detail/CVE-2021-44228).**

**But all releases including 3.5.0 contain log4j-1.2.17 which is affected by
[CVE-2019-17571](https://nvd.nist.gov/vuln/detail/CVE-2019-17571).** I cannot say if it is possible to
exploit this with JasperStarter but in any case you should update to a newer version of JasperStarter.

It has the following features:

* Run any JasperReport that needs a jdbc, csv, xml, json, jsonql or empty datasource
Expand All @@ -33,7 +39,7 @@ It has the following features:

Requirements:

* Java 1.8 or higher
* Java 1.8
* A JDBC 2.1 driver for your database


Expand Down Expand Up @@ -228,4 +234,4 @@ limitations under the License.
[Usage]:http://jasperstarter.sourceforge.net/usage.html
[Issues]:https://cenote-issues.atlassian.net/browse/JAS
[Changes]:changes.html
[jpy]:https://github.com/bcdev/jpy
[jpy]:https://github.com/bcdev/jpy
2 changes: 1 addition & 1 deletion bin/jasperstarter/bin/jasperstarter
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@
if(test -L "$0") then
auxlink=`ls -l "$0" | sed 's/^[^>]*-> //g'`
HOME_FOLDER=`dirname "$auxlink"`/..
else
else
HOME_FOLDER=`dirname "$0"`/..
fi

Expand Down
Binary file modified bin/jasperstarter/bin/jasperstarter.exe
Binary file not shown.
Empty file modified bin/jasperstarter/lib/ant-1.7.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/ant-launcher-1.7.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/antlr-2.7.7.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/antlr-3.0b5.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/argparse4j-0.5.0.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/avalon-framework-impl-4.2.0.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/barbecue-1.5-beta1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/barcode4j-2.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-anim-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-awt-util-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-bridge-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-constants-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-css-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-dom-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-ext-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-gvt-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-i18n-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-parser-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-script-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-svg-dom-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-svggen-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-util-1.9.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/batik-xml-1.9.1.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/bcprov-jdk15on-1.52.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/bcprov-jdk15on-1.68.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/castor-core-1.3.3.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/castor-core-1.4.1.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/castor-xml-1.3.3.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/castor-xml-1.4.1.jar
Binary file not shown.
Binary file not shown.
Empty file modified bin/jasperstarter/lib/commons-cli-1.0.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/commons-codec-1.10.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/commons-collections-3.2.2.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/commons-collections4-4.1.jar
Binary file not shown.
Binary file not shown.
Empty file modified bin/jasperstarter/lib/commons-digester-2.1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/commons-io-2.5.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/commons-lang-2.6.jar
100755 → 100644
Empty file.
Binary file added bin/jasperstarter/lib/commons-lang3-3.4.jar
Binary file not shown.
Empty file modified bin/jasperstarter/lib/commons-logging-1.1.1.jar
100755 → 100644
Empty file.
Binary file added bin/jasperstarter/lib/core-2.3.0.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/ecj-3.21.0.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/ecj-4.4.2.jar
Binary file not shown.
Empty file modified bin/jasperstarter/lib/groovy-all-2.4.12.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/icu4j-57.1.jar
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file removed bin/jasperstarter/lib/jackson-annotations-2.9.5.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/jackson-core-2.12.2.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/jackson-core-2.9.5.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/jackson-databind-2.12.2.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/jackson-databind-2.9.5.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/jasperreports-6.18.1.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/jasperreports-6.7.0.jar
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file not shown.
Binary file modified bin/jasperstarter/lib/jasperstarter.jar
100755 → 100644
Binary file not shown.
Empty file modified bin/jasperstarter/lib/javax.inject-1.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/jcalendar-1.4.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/jcommon-1.0.23.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/jfreechart-1.0.19.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/joda-time-2.9.9.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/jython-2.7.0.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/log4j-1.2.17.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/log4j-api-2.17.1.jar
Binary file not shown.
Binary file added bin/jasperstarter/lib/log4j-core-2.17.1.jar
Binary file not shown.
Empty file modified bin/jasperstarter/lib/poi-3.17.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/rhino-1.7.7.2.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/serializer-2.7.2.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/servlet-api-2.5.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/spring-beans-4.3.21.RELEASE.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/spring-core-4.3.21.RELEASE.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/spring-expression-4.3.21.RELEASE.jar
100755 → 100644
Empty file.
Binary file removed bin/jasperstarter/lib/stax-1.2.0.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/stax-api-1.0-2.jar
Binary file not shown.
Binary file removed bin/jasperstarter/lib/stax-api-1.0.1.jar
Binary file not shown.
Empty file modified bin/jasperstarter/lib/stringtemplate-3.0.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/xalan-2.7.2.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/xml-apis-1.3.04.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/xml-apis-ext-1.3.04.jar
100755 → 100644
Empty file.
Empty file modified bin/jasperstarter/lib/xmlgraphics-commons-2.2.jar
100755 → 100644
Empty file.

0 comments on commit 57ae498

Please sign in to comment.