CVE-2025-41240
Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing specific URLs if the application is exposed externally. The issue affects deployments using the default value of usePasswordFiles=true, which mounts secrets as files into the container filesystem.
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 0.7% (50th percentile)
- Weakness
- CWE-552
- NVD status
- Deferred
- Published
- 2025-07-24
No indexed exploits for CVE-2025-41240 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2025-41240 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.