Vulnerabilities > Quantconnect

DATE CVE VULNERABILITY TITLE RISK
2020-12-14 CVE-2020-20136 Deserialization of Untrusted Data vulnerability in Quantconnect Lean 2.3.0.0/2.4.0.1
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.
network
low complexity
quantconnect CWE-502
critical
9.8