Vulnerabilities > CVE-2020-5232 - Unspecified vulnerability in Ens.Domains Ethereum Name Service 0.0.21/0.0.22
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
NONE Summary
A user who owns an ENS domain can set a trapdoor, allowing them to transfer ownership to another user, and later regain ownership without the new owners consent or awareness. A new ENS deployment is being rolled out that fixes this vulnerability in the ENS registry.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
References
- https://github.com/ensdomains/ens/commit/36e10e71fcddcade88646821e0a57cc6c19e1ecf
- https://github.com/ensdomains/ens/commit/36e10e71fcddcade88646821e0a57cc6c19e1ecf
- https://github.com/ensdomains/ens/security/advisories/GHSA-8f9f-pc5v-9r5h
- https://github.com/ensdomains/ens/security/advisories/GHSA-8f9f-pc5v-9r5h