CVEs Blog | G5 Cyber Security

CVE-2020-20136 – QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an ins

QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-20136

Reference (s):

Exit mobile version