cnapp is a critical vulnerability affecting millions of enterprise cloud workloads and Kubernetes clusters. It exploits a flaw in the containerd runtime, allowing attackers to execute arbitrary code on the host system. As a result, attackers can gain complete control over affected systems, potentially leading to data theft, ransomware attacks, and other malicious activities.
The vulnerability is particularly severe because it affects a core component of the cloud native ecosystem. Containerd is used by major cloud providers such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure to manage containers. This means that millions of cloud workloads are potentially vulnerable to this attack.