{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": "cpe:2.3:a:pritunl:pritunl-client-electron:1.2.2550.20:*:*:*:*:*:*:*",
            "extracted_events": [
              {
                "introduced": "1.2.2550.20"
              },
              {
                "last_affected": "1.2.2550.20"
              }
            ],
            "source": [
              "CPE_STRING",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "89990d31cb9b80fb1c2de2a392f9f1e7eb8bd171"
            },
            {
              "last_affected": "89990d31cb9b80fb1c2de2a392f9f1e7eb8bd171"
            },
            {
              "fixed": "87ceeae9b8ee415541d7d71de10675e699a76e5e"
            },
            {
              "fixed": "c0aeb159351e5e99d752c27b87133eca299bdfce"
            }
          ],
          "repo": "https://github.com/pritunl/pritunl-client",
          "type": "GIT"
        }
      ],
      "versions": [
        "1.2.2550.20"
      ]
    }
  ],
  "database_specific": {},
  "details": "Pritunl Client v1.2.2550.20 contains a local privilege escalation vulnerability in the pritunl-service component. The attack vector is: malicious openvpn config. A local attacker could leverage the log and log-append along with log injection to create or append to privileged script files and execute code as root/SYSTEM.",
  "id": "CVE-2020-27519",
  "modified": "2026-08-27T03:30:34.754426825Z",
  "published": "2021-04-30T14:15:08.163Z",
  "references": [
    {
      "type": "FIX",
      "url": "https://github.com/pritunl/pritunl-client-electron/commit/87ceeae9b8ee415541d7d71de10675e699a76e5e"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pritunl/pritunl-client-electron/commit/87ceeae9b8ee415541d7d71de10675e699a76e5e#diff-5c6a264bee3576f2a147b8db70332e9a16dd43d073782cf6d32a372abb22b899"
    },
    {
      "type": "FIX",
      "url": "https://github.com/pritunl/pritunl-client-electron/commit/c0aeb159351e5e99d752c27b87133eca299bdfce"
    }
  ],
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
      "type": "CVSS_V3"
    }
  ]
}