QID 983863
QID 983863: Nodejs (npm) Security Update for @ensdomains/ens (GHSA-8f9f-pc5v-9r5h)
Security update has been released for @ensdomains/ens to fix the vulnerability. Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
A user who owns an ENS domain can set a "trapdoor", allowing them to transfer ownership to another user, and later regain ownership without the new owner's consent or awareness.
Solution
A new ENS deployment is being rolled out that fixes this vulnerability in the ENS registry. The registry is newly deployed at [0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e](https://etherscan.io/address/0x00000000000C2E074eC69A0dFb2997BA6C7d2e1e).Workaround:
Do not accept transfers of ENS domains from other users on the old registrar.
Do not accept transfers of ENS domains from other users on the old registrar.
Vendor References
- GHSA-8f9f-pc5v-9r5h -
github.com/advisories/GHSA-8f9f-pc5v-9r5h
CVEs related to QID 983863
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8f9f-pc5v-9r5h | @ensdomains/ens |
|