CVE-2020-20136

CRITICAL

Quantconnect Lean < 2.4.0.1 - Insecure Deserialization

Title source: rule

Description

QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.

Scores

CVSS v3 9.8
EPSS 0.0033
EPSS Percentile 55.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

quantconnect/lean < 2.4.0.1
nuget/QuantConnect.Common NuGet

Timeline

Published Dec 14, 2020
Tracked Since Feb 18, 2026