CVE-2019-15613
Linux openSUSE vulnerability analysis and mitigation

Overview

A bug was discovered in Nextcloud Server 17.0.1 that affects workflow rules, causing them to depend their behavior on file extensions when checking file mimetypes. The vulnerability was assigned CVE-2019-15613 and was addressed in the security advisory NC-SA-2020-002 (NVD, OpenSUSE).

Technical details

The vulnerability affects the workflow rules functionality in Nextcloud Server 17.0.1, specifically impacting how the system handles file mimetype checking. The issue was later fixed in Nextcloud version 15.0.14 as part of a security update (OpenSUSE).

Impact

The vulnerability could potentially lead to incorrect workflow rule execution based on file extensions rather than actual file types, which might result in improper file handling or security policy enforcement (NVD).

Mitigation and workarounds

The vulnerability was addressed in Nextcloud version 15.0.14. System administrators are advised to upgrade to this version or later. The fix was included in security updates for various distributions, including openSUSE and SUSE Linux Enterprise (OpenSUSE).

Additional resources


SourceThis report was generated using AI

Related Linux openSUSE vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-62291HIGH8.1
  • strongSwanstrongSwan
  • strongswan
NoYesJan 16, 2026
CVE-2026-0891HIGH8.1
  • Mozilla FirefoxMozilla Firefox
  • firefox
NoYesJan 13, 2026
CVE-2025-24528HIGH7.1
  • KerberosKerberos
  • krb5-pkinit-openssl
NoYesJan 16, 2026
CVE-2026-0890MEDIUM5.4
  • Mozilla FirefoxMozilla Firefox
  • cpe:2.3:a:mozilla:firefox_esr
NoYesJan 13, 2026
CVE-2025-43904MEDIUM4.2
  • Linux DebianLinux Debian
  • libnss_slurm2_24_11
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management