Vulnerability Description
In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was identified: using an incorrect EOR configuration can cause inaccurate parsing and leave personally identifiable information (PII) unmasked.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Perforce | Delphix Continuous Compliance | >= 2025.3.0.0, <= 2025.6.0.0 |
Related Weaknesses (CWE)
References
- https://portal.perforce.com/s/article/TB137Vendor Advisory
- https://portal.perforce.com/s/cve/a91Qi000002fThdIAE/pii-leak-due-to-change-in-eVendor Advisory
FAQ
What is CVE-2025-14591?
CVE-2025-14591 is a vulnerability with a CVSS score of 7.5 (HIGH). In Delphix Continuous Compliance version 2025.3.0 and later, following a recent bug fix to correctly handle CR+LF (Windows and DOS) End-of-Record (EOR) characters in delimited files, an issue was iden...
How severe is CVE-2025-14591?
CVE-2025-14591 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-14591?
Check the references section above for vendor advisories and patch information. Affected products include: Perforce Delphix Continuous Compliance.