Closed Issues¶
The following issues have been fixed in this release of JasperReports® Server:
| Key | Summary |
|---|---|
| JRIO-841 | Jetty and JasperReports Library documentation links are not working in JasperReports® IO application. |
| JRIO-842 | The system fails to generate the expected PDF output files during report bursting. |
| JRIO-844 | Formatting dialog does not open for Table reports. |
| JRIO-846 | The AccessibleReport reference sample located in the JasperReports® IO /samples/reports directory is outdated. |
| JRL-2112 | When a report is configured with PDF/A properties, JasperReports® Web Studio drops the linkType attribute from JRHyperlink elements. As a result, the generated hyperlinks are non-clickable. |
| JS-34719 | In JasperReports® Server, memory leak warnings during application shutdown prevented the server process from closing entirely, resulting in orphaned Java processes. |
| JS-57111 | Incorrect date shown on AdHoc view with Oracle DATE datatype. |
| JS-67108 | When an Ad Hoc View uses an Is one of filter and the Select All option is applied, saving the view as an Ad Hoc View report fails to transfer the selection. The resulting report's Input Control shows none of the values selected. |
| JS-68665 | When navigating to View > Search, the system fails to return any results if the query exceeds the maximum parameter limit allowed by SQL Server. |
| JS-75375 | On MySQL platform, the API returns wrong response code after updating permissions. |
| JS-75655 | The Report execution (Async) scenario in JasperReports Server 10.0 exhibited a substantial 30% performance degradation compared to JasperReports Server 9.0.0 during regression testing with a single user. This was attributed to a rise in average latency for all actions, and the performance impact became more pronounced with increasing concurrent users. |
| JS-75712 | Import with jobs failing on JBoss 8 platform. |
| JS-75713 | On JBoss 8 platform, when the data format of a timestamp field is altered to show date and time, the resulting format is incorrect. It shows extra comma after date value. |
| JS-75735 | On MySQL platform, the API returns an incorrect response code after the permission is updated. |
| JS-75739 | On MySQL platform, the API returns an incorrect response code after an attribute's value or description is updated. |
| JS-76888 | When accessed via the rest_v2 API endpoints, JasperReports® Server 9.0.0 fails to properly sanitize or escape the type query parameter, allowing arbitrary JavaScript to be executed in the context of the user's browser. |
| JS-77015 | When an item is deselected from the input control's "Selected" list, the report is not updated. |
| JS-77222 | Select All option fails in the Scheduler input controls for Ad Hoc View reports. |
| JS-77308 | Editing and saving an existing Domain Topic updates both its 'Modified' and 'Created' dates to the current date. |
| JS-77475 | In JasperReports® Server 9.0.0, when user role is added for ERROR MESSAGE, then key details are displayed instead of the value in error message. |
| JS-77563 | When running an Ad Hoc View report, the Input Controls panel displays locale keys for labels instead of the Input Control labels. |
| JS-77638 | Users encounter an error when attempting to access folder containing dashboard resources following an upgrade or overlay upgrade on Postgresql database. |
| JS-78095 | In JasperReports® Server 10.0.0, when a scheduled report job is deleted by a user or an administrator, the deletion is incomplete at the database level. The entries are deleted from some tables and still exist in some. |
| JS-78203 | JasperReports® Server is currently utilizing deprecated and EOL AWS-Java-SDK-1.x dependencies. |
| JS-78365 | When JasperReports® Server is configured to use an IBM DB2 database, following a standard major version upgrade or an overlay upgrade to JasperReports® Server 10.0.0, users encounter error dialog when navigating to repository folders containing Dashboard resources. |
| JS-78499 | In JasperReports® Server 9.0.0, a performance is observed when a user interacts with a report input control and selects the Select All option, specifically when the underlying dataset for that input control exceeds 100,000 (100K) values. |
| JS-78514 | JasperReports® Server 10.0.0 fails to start if the theme is configured to load directly from the local file system rather than the standard metadata repository database. |
| JS-78530 | In JasperReports® Server 10.0.0, when a report is configured with an optional input control and scheduled with the option to save as a data snapshot, the scheduled execution fails to save data snapshot during output generation. |
| JS-78612 | In JasperReports® Server 10.0.0, when a report has a valid data snapshot saved directly to the repository database, manual execution correctly pulls data from that snapshot under normal conditions. However, if the Apache Tomcat cache is cleared (deleting the contents of the |
| JS-78767 | Data source creation is blocked when using a license restricted to the FUSION feature. |
| JSS-3194 | For jasperQL, aggregate functions are not getting applied on the fields and the column is being returned as blank. |
| JSS-3531 | When copying and pasting a resource within the same directory in the Repository Explorer, the system does not offer the option to rename the duplicate file. |
| JSS-3558 | When designing reports in Jaspersoft® Studio using jasperQL, field aggregations are not working correctly. |
| JSS-3646 | Users were unable to view or access the report options within Jaspersoft® Studio. |
| JSS-3705 | Allow the table column weight property to accept negative numbers for layout configurations. |
| JSS-3706 | Fix proposed i18n properties file list in Translation Wizard. |
| JSS-3707 | Exception thrown when creating table-based reports using the New Report Wizard. |
| JSS-3710 | Jaspersoft® Studio requires internal classes to be explicitly added to the whitelist property for publishing to JasperReports® Server. |
| JSS-3730 | Reports utilizing Google Maps components are currently failing to render and are throwing timeout errors during execution. |
| JSS-3733 | After successfully publishing a report to JasperReports® Server, the Reset and Legend components fail to render on the page. |
| JSS-3734 | There is a color mismatch with Google Maps components, where the marker colors displayed in the legend box do not align with the actual markers on the map. |
| JSS-3749 | Fix the UI and input handling behavior of the date widget during report previews. |
| JRWS-1113 | When you drop an element from the Palette to the Designing Area, the alignment of the existing elements on the Designing Area is not displayed. |
| JRWS-1129 | While creating a report:
|
| JRWS-1296 | The color of the Search icons in Dataset view and in report preview are different. |
| JRWS-1300 | When you log in using Gdrive, add an image in a report and preview it, an error is displayed. However, when you save the report, you can preview it without any errors. |
| JRWS-1303 | When you log in using JackRabbit, provide a report Description in Properties view, save, and preview or close the report, the added Description is lost. |
| JRWS-1312 | When you log in using a local repository, on previewing a report from Samples, an error is displayed. |
| JRWS-1315 | On starting JasperReports® Web Studio and checking the details for JasperReports® Web Studio 3.0.1 in the command prompt, the details are not available. |
| JRWS-1317 | Log in using the local repository and open a report from the Samples folder. When you change the chart type, and revert to the original chart type of a report, the chart is not displayed on previewing a report. |
| JRWS-1130 | Two configuration properties within the dataset fail to apply or execute properly. |
| JRWS-1214 | Missing documentation for concurrent report execution. |
| JRWS-1337 | Unable to toggle Start on a new page and associated group definition checkbox properties. |
| JRWS-1405 | On previewing a report in the JasperReports® Server + JasperReports® Web Studiointegrated environment, the left-side bookmarks tab does not display correctly. |
| JRWS-1406 | Previewing a report in the JasperReports® Server + JasperReports® Web Studiointegrated environment triggers a console error and results in page alignment discrepancies when compared to the standalone JasperReports® Web Studio view. |
| JRWS-1471 | The initial report in the JasperReports® Server sample library fails to render, triggering a Headers too big HTTP error. |
| JRWS-1474 | The HTML Pro Component is displayed as unparsed text instead of HTML when rendered via Visualize.js. |
| JRWS-1486 | When exploring repositories or folders in both Standalone JasperReports® Web Studio and the JasperReports® Server integration, repository paths are no longer visible when attempting to select a data adapter. |
| JRWS-1487 | A 403 Forbidden error occurs when the system attempts to load the required fonts for FirstJasper.jrxml, preventing the report from rendering correctly. |
| JRWS-1488 | Prevented users from generating TIBCO maps within the system. |
| JRWS-1509 | Opening the Query Editor initializes the Text tab as undefined and causes an error upon switching to the Outline tab. |
| JRWS-1510 | Intermittent session/state corruption occurs when navigating from JasperReports® Server back to Jackrabbit repository, resulting in:
|
| JRWS-1513 | Switching between Text and Outline tabs in Query Editor deletes the WHERE clause. |
| JRWS-1515 | Issues in the Properties > Dataset tab:
|
| JRWS-1518 | Implemented standard multi-select behavior in Repository view (Cmd/Ctrl and Shift clicks). |
| JRWS-1519 | The jrws.jrs.token.login.url.js file was ignored during token-based SSO. The UIService servlet has been updated to correctly pass this property from jrws.properties to the frontend. |
| JRWS-1520 | Clean up JasperReports® Web Studio by removing all references to the TibcoMaps component. |
| JRWS-1533 | A 500 Internal Server Error is triggered when a user attempts to log in using their GitHub account. |
| JRWS-1534 | Update the JasperReports® Web Studio implementation to adopt and integrate JasperReports® Library export tags. |
| JRWS-1537 | For Integrated JasperReports® Web Studio, clicking Get Metadata triggers a 500 Internal Server Error and fails to retrieve data for the selected data adapter. |
| JRWS-1539 | When running JasperReports® Web Studio in Standalone mode, statistics are not being captured or tracked for the creation of data adapters. |
| JRWS-1542 | About dialog shows incorrect product details when license file is missing. |
Security Issues¶
The following security issues have been fixed in this release of JasperReports® Server:
| Key | Area of the Product Affected | Type of Vulnerability | Description and Impact on Users |
|---|---|---|---|
| JSSEC-163/ JRL-2103 | Configuration files | Access to sensitive files | The server's insecure handling of untrusted object serialization allowed attackers to bypass type validation restrictions, enabling remote code execution via a manipulated report file. The attacker was able to trigger arbitrary code execution by uploading a malicious JRXML report that forces the server to fetch and parse a crafted
|
| JS-70720 | N/A | Dependency on third-party libraries | Upgraded aws-java-sdk-core-1.11.505.jar to resolve the following CVE:
|
| JS-76514 | N/A | Dependency on third-party libraries | Upgraded jackson-core-2.13.4.jar to resolve the following CVE:
|
| JS-76953 | N/A | Dependency on third-party libraries | Upgraded commons-lang3-3.0.jar to resolve the following CVE:
|
| JS-77826 | N/A | Dependency on third-party libraries | Upgraded Spring JARs to resolve the following CVE:
|
| JS-77889 | N/A | Dependency on third-party libraries | Upgraded underscore.string to resolve the following CVE:
|
| JS-78055 | N/A | Dependency on third-party libraries | Upgraded Log4j2 JARs to resolve the following CVE:
|
| JS-78254 | N/A | Dependency on third-party libraries | Upgraded netty-codec-http-4.1.127.Final.jar to resolve the following CVE:
|
| JS-78653 | N/A | Dependency on third-party libraries | Upgraded the Spring security JARs to resolve the following CVE:
|
| JS-78719 | N/A | Dependency on third-party libraries | Upgraded Netty jar to 4.1.132.Final and 4.2.10.Final to resolve the following CVE:
|
| JS-79040 | N/A | Dependency on third-party libraries | Upgraded Log4j2 JARs to resolve the following CVEs:
|
| JSS-3742 | N/A | Dependency on third-party libraries | Upgraded Log4j2 JARs to resolve the following CVEs:
|
| JRWS-1470 | HTTP protocol | Cross-Site Request Forgery (CSRF) | Verified and corrected CSRF behavior for JasperReports® Web Studio when embedded within JasperReports® Server, addressing previous integration issues. |
| JRWS-1504 | N/A | Dependency on third-party libraries | Upgraded log4j2 JARs for jrws-jrio-jrs.war and jrws-repository-jrs.war to resolve the following CVE:
|
For information about cases fixed in previous releases, see that version's release notes. For information about your specific cases, visit Jaspersoft Technical Support.