StackRadar

jasperreports Helm chart

helm-dojo

Scored 25 Sept 2026

JasperReports Server is a stand-alone and embeddable reporting server. It is a central information hub, with reporting and analytics that can be embedded into web and mobile applications.

Latest 8.0.0-v1.3app version 8-v1.3 0Artifact Hub

jasperreports 8.0.0-v1.3 deploys 2 container images: palopalepalo/jasperreports and bitnami/mariadb. Across the 1 measured, 421 findings — 5 critical, 21 high — 8 on CISA KEV. The highest contribution is BIT-tomcat-2025-24813 in tomcat 9.0.71-10, fixed in 9.0.99.

Radar Score

6,561521114281

421 findings over 1 of 2 images measured

KEV ×8 confirmed exploited

Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.

Container images

2 images
ImageTagVulnerabilitiesRadar Score
palopalepalo/jasperreports8-v1.35211142816,561
bitnami/mariadb10.6.12-debian-11-r9—unmeasured

Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.

Vulnerabilities

421 distinct across the version’s images
SeverityAdvisoryPackageFixed in
CriticalBIT-tomcat-2025-24813KEVtomcat@9.0.71-109.0.99
CriticalGHSA-crg9-44h2-xw35KEVactivemq-client@5.16.25.16.7
CriticalGHSA-599f-7c49-w659commons-text@1.81.10.0
CriticalGHSA-xj57-8qj4-c4m6commons-configuration2@2.72.8.0
CriticalBIT-tomcat-2023-44487KEVtomcat@9.0.71-108.5.94
HighGHSA-9339-86wc-4qgfxalan@2.7.22.7.3
HighGHSA-4wrc-f8pq-fpqpspring-web@5.2.21.RELEASE6.0.0
HighBIT-tomcat-2024-50379tomcat@9.0.71-109.0.98
HighBIT-tomcat-2025-55752tomcat@9.0.71-109.0.109
HighGHSA-g5vr-rgqm-vf78spring-webmvc@5.2.21.RELEASEno fix listed
HighGHSA-76h9-2vwh-w278mina-core@2.1.62.1.10
HighGHSA-vv7r-c36w-3prjcommons-fileupload@1.3.31.6.0
HighGHSA-hfrx-6qgj-fp6ccommons-fileupload@1.3.31.5
HighGHSA-qppj-fm5r-hxr3KEVtomcat-coyote@9.0.719.0.81
HighBIT-tomcat-2025-48988tomcat@9.0.71-109.0.106
HighGHSA-hh32-7344-cg2fspring-security-web@4.2.19.RELEASE5.4.11
HighGHSA-hh32-7344-cg2fspring-security-core@4.2.19.RELEASE5.4.11
HighGHSA-xr7r-f8xq-vfvvgithub.com/opencontainers/runc@v1.1.01.1.12
HighBIT-tomcat-2024-24549tomcat@9.0.71-108.5.99
HighGHSA-7w75-32cg-r6g2tomcat-coyote@9.0.719.0.86
HighBIT-tomcat-2025-55754tomcat@9.0.71-109.0.109
HighBIT-tomcat-2024-56337tomcat@9.0.71-109.0.98
HighDLA-4104-1KEVfreetype@2.10.4+dfsg-1+deb11u12.10.4+dfsg-1+deb11u2
HighDLA-4323-1KEVgit@1:2.30.2-1+deb11u21:2.30.2-1+deb11u5
HighDSA-5514-1KEVglibc@2.31-13+deb11u52.31-13+deb11u7
HighDSA-5570-1KEVnghttp2@1.43.0-11.43.0-1+deb11u1
MediumDLA-3859-1systemd@247.3-7+deb11u1247.3-7+deb11u6
MediumGO-2024-2687stdlib@go1.19.61.21.9
MediumBIT-tomcat-2024-52316tomcat@9.0.71-109.0.96
MediumDSA-5673-1glibc@2.31-13+deb11u52.31-13+deb11u9
MediumDLA-3898-1nghttp2@1.43.0-11.43.0-1+deb11u2
MediumGHSA-3f7h-mf4q-vrm4woodstox-core@6.2.76.4.0
MediumDSA-5523-1curl@7.74.0-1.3+deb11u77.74.0-1.3+deb11u10
MediumGHSA-24rp-q3w6-vc56postgresql@42.5.442.5.5
MediumDSA-5417-1openssl@1.1.1n-0+deb11u41.1.1n-0+deb11u5
MediumBIT-tomcat-2025-31651tomcat@9.0.71-109.0.104
MediumGHSA-whxr-3p84-rf3cactivemq-client@5.16.25.16.8
MediumGHSA-f62v-xpxf-3v68ant@1.9.41.10.9
MediumDLA-3942-1openssl@1.1.1n-0+deb11u41.1.1n-0+deb11u6
MediumDLA-3942-2openssl@1.1.1n-0+deb11u41.1.1w-0+deb11u2
MediumDLA-3867-1git@1:2.30.2-1+deb11u21:2.30.2-1+deb11u3
MediumGHSA-gq28-h5vg-8prxspring-security-web@4.2.19.RELEASE5.2.9
MediumGHSA-ccgv-vj62-xf9hspring-web@5.2.21.RELEASEno fix listed
MediumGHSA-57j2-w4cx-62h2jackson-databind@2.11.12.12.6.1
MediumBIT-tomcat-2024-34750tomcat@9.0.71-109.0.90
MediumGHSA-wm9w-rjj3-j356tomcat-coyote@9.0.719.0.90
MediumGHSA-98qh-xjc8-98pqpostgresql@42.5.442.7.11
MediumBIT-mysql-client-2026-44170mysql-client@10.6.12-110.6.26
MediumBIT-tomcat-2026-41293tomcat@9.0.71-1010.1.55
MediumGHSA-r29c-68gh-xp6xtomcat-coyote@9.0.719.0.118

Indexed versions

VersionPublishedApp versionVulnerabilitiesRadar Score
8.0.0-v1.3latest—8-v1.35211142816,561

The latest version and the previous major, as selected nightly from the repository’s index.

README badge
[![Radar Score](https://charts.stackradar.io/badge/helm-dojo/jasperreports.svg)](https://charts.stackradar.io/charts/helm-dojo/jasperreports)

Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.

helm v3.16.4 · syft 1.42.1 · rendered 25 Sept 2026 · scanned 25 Sept 2026 · advisories as of 25 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.