SUSE 5494 Published by

SUSE has implemented multiple security updates, which include libtiff-devel, jupyter-bqplot-jupyterlab, jetty-annotations, and terragrunt:

openSUSE-SU-2025:15487-1: moderate: libtiff-devel-32bit-4.7.0-8.1 on GA media
openSUSE-SU-2025:15485-1: moderate: jupyter-bqplot-jupyterlab-0.5.46-12.1 on GA media
openSUSE-SU-2025:15483-1: moderate: jetty-annotations-9.4.58-1.1 on GA media
openSUSE-SU-2025:15486-1: moderate: terragrunt-0.85.1-1.1 on GA media




openSUSE-SU-2025:15487-1: moderate: libtiff-devel-32bit-4.7.0-8.1 on GA media


# libtiff-devel-32bit-4.7.0-8.1 on GA media

Announcement ID: openSUSE-SU-2025:15487-1
Rating: moderate

Cross-References:

* CVE-2024-13978
* CVE-2025-8534
* CVE-2025-9165

CVSS scores:

* CVE-2024-13978 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
* CVE-2024-13978 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
* CVE-2025-8534 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-8534 ( SUSE ): 2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
* CVE-2025-9165 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
* CVE-2025-9165 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves 3 vulnerabilities can now be installed.

## Description:

These are all security issues fixed in the libtiff-devel-32bit-4.7.0-8.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* libtiff-devel 4.7.0-8.1
* libtiff-devel-32bit 4.7.0-8.1
* libtiff6 4.7.0-8.1
* libtiff6-32bit 4.7.0-8.1
* tiff 4.7.0-8.1

## References:

* https://www.suse.com/security/cve/CVE-2024-13978.html
* https://www.suse.com/security/cve/CVE-2025-8534.html
* https://www.suse.com/security/cve/CVE-2025-9165.html



openSUSE-SU-2025:15485-1: moderate: jupyter-bqplot-jupyterlab-0.5.46-12.1 on GA media


# jupyter-bqplot-jupyterlab-0.5.46-12.1 on GA media

Announcement ID: openSUSE-SU-2025:15485-1
Rating: moderate

Cross-References:

* CVE-2025-9287

CVSS scores:

* CVE-2025-9287 ( SUSE ): 9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
* CVE-2025-9287 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jupyter-bqplot-jupyterlab-0.5.46-12.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jupyter-bqplot-jupyterlab 0.5.46-12.1
* jupyter-bqplot-notebook 0.5.46-12.1
* python311-bqplot 0.12.45-12.1

## References:

* https://www.suse.com/security/cve/CVE-2025-9287.html



openSUSE-SU-2025:15483-1: moderate: jetty-annotations-9.4.58-1.1 on GA media


# jetty-annotations-9.4.58-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15483-1
Rating: moderate

Cross-References:

* CVE-2025-5115

CVSS scores:

* CVE-2025-5115 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
* CVE-2025-5115 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the jetty-annotations-9.4.58-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* jetty-annotations 9.4.58-1.1
* jetty-ant 9.4.58-1.1
* jetty-cdi 9.4.58-1.1
* jetty-client 9.4.58-1.1
* jetty-continuation 9.4.58-1.1
* jetty-deploy 9.4.58-1.1
* jetty-fcgi 9.4.58-1.1
* jetty-http 9.4.58-1.1
* jetty-http-spi 9.4.58-1.1
* jetty-io 9.4.58-1.1
* jetty-jaas 9.4.58-1.1
* jetty-jmx 9.4.58-1.1
* jetty-jndi 9.4.58-1.1
* jetty-jsp 9.4.58-1.1
* jetty-minimal-javadoc 9.4.58-1.1
* jetty-openid 9.4.58-1.1
* jetty-plus 9.4.58-1.1
* jetty-project 9.4.58-1.1
* jetty-proxy 9.4.58-1.1
* jetty-quickstart 9.4.58-1.1
* jetty-rewrite 9.4.58-1.1
* jetty-security 9.4.58-1.1
* jetty-server 9.4.58-1.1
* jetty-servlet 9.4.58-1.1
* jetty-servlets 9.4.58-1.1
* jetty-start 9.4.58-1.1
* jetty-util 9.4.58-1.1
* jetty-util-ajax 9.4.58-1.1
* jetty-webapp 9.4.58-1.1
* jetty-xml 9.4.58-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-5115.html



openSUSE-SU-2025:15486-1: moderate: terragrunt-0.85.1-1.1 on GA media


# terragrunt-0.85.1-1.1 on GA media

Announcement ID: openSUSE-SU-2025:15486-1
Rating: moderate

Cross-References:

* CVE-2025-8959

Affected Products:

* openSUSE Tumbleweed

An update that solves one vulnerability can now be installed.

## Description:

These are all security issues fixed in the terragrunt-0.85.1-1.1 package on the GA media of openSUSE Tumbleweed.

## Package List:

* openSUSE Tumbleweed:
* terragrunt 0.85.1-1.1
* terragrunt-bash-completion 0.85.1-1.1
* terragrunt-zsh-completion 0.85.1-1.1

## References:

* https://www.suse.com/security/cve/CVE-2025-8959.html