Below has Incorrect Permission Assignment for Critical Resource
High severity
GitHub Reviewed
Published
Mar 11, 2025
in
facebookincubator/below
•
Updated Mar 12, 2025
Description
Published to the GitHub Advisory Database
Mar 11, 2025
Reviewed
Mar 11, 2025
Last updated
Mar 12, 2025
Impact
A privilege escalation vulnerability existed in the Below service prior to v0.9.0 due to the creation of a world-writable directory at /var/log/below. This could have allowed local unprivileged users to escalate to root privileges through symlink attacks that manipulate files such as /etc/shadow.
Patches
facebookincubator/below@10e73a2
This is included in version 0.9.0
Workarounds
Change the permission on
/var/log/below
manuallyReferences
https://www.facebook.com/security/advisories/cve-2025-27591
https://www.cve.org/CVERecord?id=CVE-2025-27591
References