ZeroHour

CVE-2020-20136

PoC
CVSS 3.1
9.8 critical
EPSS
2%p73
Published
()
Modified
Description

QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.

Vendors
quantconnect
Products
lean
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.