Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-9582.json"