cve/2020/CVE-2020-20136.md
2024-05-25 21:48:12 +02:00

659 B

CVE-2020-20136

Description

QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library.

POC

Reference

Github

No PoCs found on GitHub currently.