CRITICAL
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library
Published Dec 14, 2020
9.8
CRITICALCVSS 3.1
EPSS 1.54%
Description
Affected products
Remediation
References (3)
Change history (0)
No recorded changes yet.