jasperreports Helm chart
helm-dojoScored 25 Sept 2026
JasperReports Server is a stand-alone and embeddable reporting server. It is a central information hub, with reporting and analytics that can be embedded into web and mobile applications.
Latest 8.0.0-v1.3app version 8-v1.3 0Artifact Hub
jasperreports 8.0.0-v1.3 deploys 2 container images: palopalepalo/jasperreports and bitnami/mariadb. Across the 1 measured, 421 findings — 5 critical, 21 high — 8 on CISA KEV. The highest contribution is BIT-tomcat-2025-24813 in tomcat 9.0.71-10, fixed in 9.0.99.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Container images
| Image | Tag | Vulnerabilities | Radar Score |
|---|---|---|---|
| palopalepalo/ | 8-v1.3 | 521114281 | 6,561 |
| bitnami/ | 10.6.12-debian-11-r9 | — | unmeasured |
Rendered with the chart’s default values for linux/amd64. Optional subcharts, images set by operator flags and images inside CRD payloads are not seen and are counted as unmeasured.
Vulnerabilities
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Critical | BIT-tomcat-2025-24813KEV | tomcat | 9.0.99 |
| Critical | GHSA-crg9-44h2-xw35KEV | activemq-client | 5.16.7 |
| Critical | GHSA-599f-7c49-w659 | commons-text | 1.10.0 |
| Critical | GHSA-xj57-8qj4-c4m6 | commons-configuration2 | 2.8.0 |
| Critical | BIT-tomcat-2023-44487KEV | tomcat | 8.5.94 |
| High | GHSA-9339-86wc-4qgf | xalan | 2.7.3 |
| High | GHSA-4wrc-f8pq-fpqp | spring-web | 6.0.0 |
| High | BIT-tomcat-2024-50379 | tomcat | 9.0.98 |
| High | BIT-tomcat-2025-55752 | tomcat | 9.0.109 |
| High | GHSA-g5vr-rgqm-vf78 | spring-webmvc | no fix listed |
| High | GHSA-76h9-2vwh-w278 | mina-core | 2.1.10 |
| High | GHSA-vv7r-c36w-3prj | commons-fileupload | 1.6.0 |
| High | GHSA-hfrx-6qgj-fp6c | commons-fileupload | 1.5 |
| High | GHSA-qppj-fm5r-hxr3KEV | tomcat-coyote | 9.0.81 |
| High | BIT-tomcat-2025-48988 | tomcat | 9.0.106 |
| High | GHSA-hh32-7344-cg2f | spring-security-web | 5.4.11 |
| High | GHSA-hh32-7344-cg2f | spring-security-core | 5.4.11 |
| High | GHSA-xr7r-f8xq-vfvv | github.com/ | 1.1.12 |
| High | BIT-tomcat-2024-24549 | tomcat | 8.5.99 |
| High | GHSA-7w75-32cg-r6g2 | tomcat-coyote | 9.0.86 |
| High | BIT-tomcat-2025-55754 | tomcat | 9.0.109 |
| High | BIT-tomcat-2024-56337 | tomcat | 9.0.98 |
| High | DLA-4104-1KEV | freetype | 2.10.4+dfsg-1+deb11u2 |
| High | DLA-4323-1KEV | git | 1:2.30.2-1+deb11u5 |
| High | DSA-5514-1KEV | glibc | 2.31-13+deb11u7 |
| High | DSA-5570-1KEV | nghttp2 | 1.43.0-1+deb11u1 |
| Medium | DLA-3859-1 | systemd | 247.3-7+deb11u6 |
| Medium | GO-2024-2687 | stdlib | 1.21.9 |
| Medium | BIT-tomcat-2024-52316 | tomcat | 9.0.96 |
| Medium | DSA-5673-1 | glibc | 2.31-13+deb11u9 |
| Medium | DLA-3898-1 | nghttp2 | 1.43.0-1+deb11u2 |
| Medium | GHSA-3f7h-mf4q-vrm4 | woodstox-core | 6.4.0 |
| Medium | DSA-5523-1 | curl | 7.74.0-1.3+deb11u10 |
| Medium | GHSA-24rp-q3w6-vc56 | postgresql | 42.5.5 |
| Medium | DSA-5417-1 | openssl | 1.1.1n-0+deb11u5 |
| Medium | BIT-tomcat-2025-31651 | tomcat | 9.0.104 |
| Medium | GHSA-whxr-3p84-rf3c | activemq-client | 5.16.8 |
| Medium | GHSA-f62v-xpxf-3v68 | ant | 1.10.9 |
| Medium | DLA-3942-1 | openssl | 1.1.1n-0+deb11u6 |
| Medium | DLA-3942-2 | openssl | 1.1.1w-0+deb11u2 |
| Medium | DLA-3867-1 | git | 1:2.30.2-1+deb11u3 |
| Medium | GHSA-gq28-h5vg-8prx | spring-security-web | 5.2.9 |
| Medium | GHSA-ccgv-vj62-xf9h | spring-web | no fix listed |
| Medium | GHSA-57j2-w4cx-62h2 | jackson-databind | 2.12.6.1 |
| Medium | BIT-tomcat-2024-34750 | tomcat | 9.0.90 |
| Medium | GHSA-wm9w-rjj3-j356 | tomcat-coyote | 9.0.90 |
| Medium | GHSA-98qh-xjc8-98pq | postgresql | 42.7.11 |
| Medium | BIT-mysql-client-2026-44170 | mysql-client | 10.6.26 |
| Medium | BIT-tomcat-2026-41293 | tomcat | 10.1.55 |
| Medium | GHSA-r29c-68gh-xp6x | tomcat-coyote | 9.0.118 |
Indexed versions
| Version | Published | App version | Vulnerabilities | Radar Score |
|---|---|---|---|---|
| 8.0.0-v1.3latest | — | 8-v1.3 | 521114281 | 6,561 |
The latest version and the previous major, as selected nightly from the repository’s index.
README badge
Markdown. The badge shows the latest version’s band and Radar Score, refreshed daily.