Get a Demo

Let's Patch It!

Book a short call with one our specialists, we'll walk you through how Endor Patches work, and ask you a few questions about your environment (like your primary programming languages and repository management). We'll also send you an email right after you fill out the form, feel free to reply with any questions you have in advance!

CVE

CVE-2025-41240

Mounted Kubernetes Secrets under a predictable path located within the web server document root
Back to all
CVE

CVE-2025-41240

Mounted Kubernetes Secrets under a predictable path located within the web server document root

Three Bitnami Helm charts mount Kubernetes Secrets under a predictable path (/opt/bitnami/*/secrets) that is located within the web server document root.

In affected versions, this can lead to unauthenticated access to sensitive credentials via HTTP/S. A remote attacker could retrieve these secrets by accessing specific URLs if the application is exposed externally. The issue affects deployments using the default value of usePasswordFiles=true, which mounts secrets as files into the container filesystem.

Package Versions Affected

Package Version
patch Availability
No items found.

Automatically patch vulnerabilities without upgrading

Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request

CVSS Version

Severity
Base Score
CVSS Version
Score Vector
C
H
U
10
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
C
H
U
-

Related Resources

No items found.

References

https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/41xxx/CVE-2025-41240.json, https://github.com/bitnami/charts/security/advisories/GHSA-wgg9-9qgw-529w, https://nvd.nist.gov/vuln/detail/CVE-2025-41240

Severity

10

CVSS Score
0
10

Basic Information

Base CVSS
10
EPSS Probability
0.00702%
EPSS Percentile
0.50548%
Introduced Version
d31ec15591a7ed93fdb9087a87a87ec436084ac4
Fix Available
3c4765c455c923166e5e66781f85450bcbb1efa2

Fix Critical Vulnerabilities Instantly

Secure your app without upgrading.
Fix Without Upgrading