QuantConnect Lean vulnerable to insecure deserialization
Critical severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Jul 20, 2023
Description
Published by the National Vulnerability Database
Dec 14, 2020
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 20, 2023
Last updated
Jul 20, 2023
QuantConnect Lean versions from 2.3.0.0 to 2.4.0.1 are affected by an insecure deserialization vulnerability due to insecure configuration of TypeNameHandling property in Json.NET library. One may avoid this issue by only running Lean in an environment where data provided is trusted.
References