Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a security mitigation bypass vulnerability. Successful exploitation could lead to arbitrary code execution.
{
    "cpes": [
        "cpe:2.3:a:magento:magento:*:*:*:*:commerce:*:*:*",
        "cpe:2.3:a:magento:magento:*:*:*:*:community:*:*:*",
        "cpe:2.3:a:magento:magento:*:*:*:*:open_source:*:*:*",
        "cpe:2.3:a:magento:magento:*:*:*:*:enterprise:*:*:*"
    ],
    "severity": "Critical"
}