CVE-2020-20136
CRITICALQuantconnect Lean < 2.4.0.1 - Insecure Deserialization
Title source: ruleDescription
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
Scores
CVSS v3
9.8
EPSS
0.0033
EPSS Percentile
55.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
quantconnect/lean
< 2.4.0.1
nuget/QuantConnect.Common
NuGet
Timeline
Published
Dec 14, 2020
Tracked Since
Feb 18, 2026