Описание
A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new owners consent or awareness. A new ENS deployment is being rolled out that fixes this vulnerability in the ENS registry.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.1.0 (включая)
cpe:2.3:a:ens.domains:ethereum_name_service:*:*:*:*:*:*:*:*
EPSS
Процентиль: 50%
0.00269
Низкий
8.7 High
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-285
NVD-CWE-Other
Связанные уязвимости
CVSS3: 8.7
github
около 6 лет назад
Malicious takeover of previously owned ENS names
EPSS
Процентиль: 50%
0.00269
Низкий
8.7 High
CVSS3
4.9 Medium
CVSS2
Дефекты
CWE-285
NVD-CWE-Other