CVE-2019-15613: Nextcloud Server

High severity, CVSS 8.0. EPSS: 1.1% chance of exploitation in the next 30 days.

A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.

Affected products

  • Nextcloud Nextcloud Server: before 15.0.14 (fixed in 15.0.14); from 16.0.0, before 16.0.7 (fixed in 16.0.7); from 17.0.0, before 17.0.2 (fixed in 17.0.2)
  • Opensuse Backports: version sle-15 only

Published 2020-02-04. Last modified 2026-06-17.