
Cloud Vulnerability DB
A community-led vulnerabilities database
A bug was discovered in Nextcloud Server 17.0.1 that affects workflow rules, causing them to depend their behavior on file extensions when checking file mimetypes. The vulnerability was assigned CVE-2019-15613 and was addressed in the security advisory NC-SA-2020-002 (NVD, OpenSUSE).
The vulnerability affects the workflow rules functionality in Nextcloud Server 17.0.1, specifically impacting how the system handles file mimetype checking. The issue was later fixed in Nextcloud version 15.0.14 as part of a security update (OpenSUSE).
The vulnerability could potentially lead to incorrect workflow rule execution based on file extensions rather than actual file types, which might result in improper file handling or security policy enforcement (NVD).
The vulnerability was addressed in Nextcloud version 15.0.14. System administrators are advised to upgrade to this version or later. The fix was included in security updates for various distributions, including openSUSE and SUSE Linux Enterprise (OpenSUSE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."