Below has Incorrect Permission Assignment for Critical Resource
High severity
GitHub Reviewed
Published
Mar 11, 2025
in
facebookincubator/below
•
Updated Mar 12, 2025
Description
Published by the National Vulnerability Database
Mar 11, 2025
Published to the GitHub Advisory Database
Mar 11, 2025
Reviewed
Mar 11, 2025
Last updated
Mar 12, 2025
Impact
A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
Patches
facebookincubator/below@10e73a2
This is included in version 0.9.0
Workarounds
Change the permission on
/var/log/below
manuallyReferences
https://www.facebook.com/security/advisories/cve-2025-27591
https://www.cve.org/CVERecord?id=CVE-2025-27591
References