CVE-2022-28544

MEDIUM

Galaxy store <4.5.40.5 - Path Traversal

Title source: llm
STIX 2.1

Description

Path traversal vulnerability in unzip method of InstallAgentCommonHelper in Galaxy store prior to version 4.5.40.5 allows attacker to access the file of Galaxy store.

References (1)

Core 1
Core References

Scores

CVSS v3 6.2
EPSS 0.0029
EPSS Percentile 52.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

CWE
CWE-22
Status published
Products (1)
samsung/galaxy_store < 4.5.40.5
Published Apr 11, 2022
Tracked Since Feb 18, 2026