CVE Vulnerabilities

CVE-2019-15613

Insufficient Verification of Data Authenticity

Published: Feb 04, 2020 | Modified: May 11, 2023
CVSS 3.x
8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A bug in Nextcloud Server 17.0.1 causes the workflow rules to depend their behaviour on the file extension when checking file mimetypes.

Weakness

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Affected Software

Name Vendor Start Version End Version
Nextcloud_server Nextcloud * 15.0.14 (excluding)
Nextcloud_server Nextcloud 16.0.0 (including) 16.0.7 (excluding)
Nextcloud_server Nextcloud 17.0.0 (including) 17.0.2 (excluding)

References