CVE-2025-41240
Mounted Kubernetes Secrets under a predictable path located within the web server document root
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root.
In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing specific URLs if the application is exposed externally. The issue affects deployments using the default value of usePasswordFiles=true, which mounts secrets as files into the container filesystem.
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing specific URLs if the application is exposed externally. The issue affects deployments using the default value of usePasswordFiles=true, which mounts secrets as files into the container filesystem.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-04-16 CVE Reserved
- 2025-07-24 CVE Published
- 2025-07-25 CVE Updated
- 2025-07-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-552: Files or Directories Accessible to External Parties
CAPEC
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
VMware Search vendor "VMware" | Bitnamicharts/appsmith Search vendor "VMware" for product "Bitnamicharts/appsmith" | >= 21.2.0 <= 22.0.4 Search vendor "VMware" for product "Bitnamicharts/appsmith" and version " >= 21.2.0 <= 22.0.4" | en |
Affected
| ||||||
VMware Search vendor "VMware" | Bitnamicharts/drupal Search vendor "VMware" for product "Bitnamicharts/drupal" | >= 5.2.0 < 6.0.19 Search vendor "VMware" for product "Bitnamicharts/drupal" and version " >= 5.2.0 < 6.0.19" | en |
Affected
| ||||||
VMware Search vendor "VMware" | Bitnamicharts/wordpress Search vendor "VMware" for product "Bitnamicharts/wordpress" | >= 24.2.0 < 25.0.4 Search vendor "VMware" for product "Bitnamicharts/wordpress" and version " >= 24.2.0 < 25.0.4" | en |
Affected
|