CVE-2022-28544: Path Traversal
Published Apr 11, 2022
·Updated
Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.
Affected Software
1 affected component
Samsung Galaxy Store<4.5.40.5
Event History
Apr 11, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2022-28544?
CVE-2022-28544 is a high-severity vulnerability that exposes the Galaxy Store to path traversal attacks.
2
How do I fix CVE-2022-28544?
To fix CVE-2022-28544, update the Galaxy Store to version 4.5.40.5 or later.
3
Which versions of Galaxy Store are affected by CVE-2022-28544?
CVE-2022-28544 affects all versions of Galaxy Store prior to version 4.5.40.5.
4
What type of attack can be executed using CVE-2022-28544?
CVE-2022-28544 allows attackers to exploit a path traversal vulnerability to access sensitive files within the Galaxy Store.
5
Who is vulnerable to CVE-2022-28544?
Users of Samsung Galaxy Store versions below 4.5.40.5 are vulnerable to CVE-2022-28544.