Impact
A flaw in goshs' WebDAV handling allows a client to issue a MOVE with the Overwrite: T header to delete or overwrite a target file when the server is started with the --no-delete option. This constitutes an improper authorization weakness (CWE‑284) that can lead to data loss or unauthorized modification of stored files. The CVSS score of 9.1 highlights the severity of the impact.
Affected Systems
All installations of the goshs file server running a version earlier than 2.1.4 are affected. The issue applies to the product distributed by the goshs‑labs team.
Risk and Exploitability
The EPSS score of less than 1% indicates that widespread exploitation is currently unlikely, but the vulnerability is present in the publicly reachable web interface and can be exercised over the network by a client that can send WebDAV requests. It is not listed in the CISA KeV catalog, yet its critical CVSS rating and the ability to overwrite or delete arbitrary files make it a high‑risk problem for environments where goshs is exposed to the internet or untrusted networks.
OpenCVE Enrichment
Github GHSA