First published: Tue Feb 04 2020(Updated: )
A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | <15.0.14 | |
Nextcloud Nextcloud Server | >=16.0.0<16.0.7 | |
Nextcloud Nextcloud Server | >=17.0.0<17.0.2 | |
Opensuse Backports | =sle-15-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-15613 is a vulnerability in Nextcloud Server 17.0.1 that causes workflow rules to depend on file extensions when checking file mimetypes.
CVE-2019-15613 affects Nextcloud Server versions 15.0.14, 16.0.0 to 16.0.7, and 17.0.0 to 17.0.2.
CVE-2019-15613 has a severity of high with a CVSS score of 8.
To fix CVE-2019-15613, update Nextcloud Server to a version that is not affected by the vulnerability.
You can find more information about CVE-2019-15613 in the references provided: http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.html, http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.html, and https://hackerone.com/reports/697959.