Security Advisory

CVE-2020-20136

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-12-14 18:30:43
Last updated 2024-08-04 14:15:29
Assigner mitre
State PUBLISHED

Description

QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.