CVE-2019-15613: Input Validation
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-15613?
CVE-2019-15613 is a vulnerability in Nextcloud Server 17.0.1 that causes workflow rules to depend on file extensions when checking file mimetypes.
How does CVE-2019-15613 affect Nextcloud Server?
CVE-2019-15613 affects Nextcloud Server versions 15.0.14, 16.0.0 to 16.0.7, and 17.0.0 to 17.0.2.
What is the severity of CVE-2019-15613?
CVE-2019-15613 has a severity of high with a CVSS score of 8.
How can I fix CVE-2019-15613?
To fix CVE-2019-15613, update Nextcloud Server to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2019-15613?
You can find more information about CVE-2019-15613 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.html, http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.html, and https://hackerone.com/reports/697959.