CVE-2020-20136

CRITICAL

QuantConnect Lean 2.3.0.0-2.4.0.1 - Deserialization of Untrusted Data via Json.NET TypeNameHandling Misconfiguration

Title source: llm
STIX 2.1

Description

QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/QuantConnect/Lean/issues/3537

Scores

CVSS v3 9.8
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (2)
nuget/QuantConnect.Common 2.3.0.0NuGet
quantconnect/lean 2.3.0.0 - 2.4.0.1
Published Dec 14, 2020
Tracked Since Feb 18, 2026