Omarchy에서 사용자가 root 권한을 획득할 수 있는 취약점이 발견되었다.
Omarchy의 기본 Docker 설정으로 인해 데스크톱 세션의 모든 프로그램이 암호나 권한 확인 없이 root 권한을 얻을 수 있었다. 이 문제는 사용자가 Linux의 docker 그룹에 추가되어 root Docker 데몬의 소켓에 접근 가능해진 것이 원인이다. 비공식 제보 후 이 취약점은 수정되었다.
A vulnerability allowed users to gain root access in Omarchy due to Docker settings.
In Omarchy, a security vulnerability allowed nearly all desktop session programs to gain root access without password or privilege checks due to its default Docker settings. The issue stemmed from adding a standard user to the Linux docker group, which granted access to the root Docker daemon socket. The vulnerability has since been fixed following an unofficial report.