← Back to CVE List
Vulnerability Intelligence Report
Mounted Kubernetes Secrets under a predictable path located within the web server document root

CVE-2025-41240

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root. In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing specific URLs if the application is exposed externally. The issue affects deployments using the default value of usePasswordFiles=true, which mounts secrets as files into the container filesystem.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:0.70%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-552 ↗CWE-552 Files or Directories Accessible to External Parties

Affected Products & Versions

Vendor Product Affected Versions
VMware bitnamicharts/appsmith 21.2.0 <= 22.0.4 (affected)
VMware bitnamicharts/drupal 5.2.0 < 6.0.19 (affected)
VMware bitnamicharts/wordpress 24.2.0 < 25.0.4 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.696%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVMware by Broadcom · Vendor · USA
Reserved2025-04-16T09:30:17
Published2025-07-24T06:42:25
Patch Date2025-07-23
Last Updated2026-02-26T17:50:15

LINK COPIED TO CLIPBOARD