Impact
A vulnerability in HdrHistogram up to version 2.2.2 allows manipulation of the Count argument in recordValueWithCount to corrupt the library’s internal state. The flaw is classified as CWE‑371 and CWE‑1284, and the attack can only be performed from a local environment.
Affected Systems
All releases of HdrHistogram up to and including version 2.2.2 are affected. The vulnerability is fixed in future releases, so any deployment that incorporates an earlier version remains susceptible until the flaw is patched.
Risk and Exploitability
The CVSS score of 4.8 indicates low severity, and the EPSS score of < 1 % shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog and can only be abused from a local environment. Thus the risk is confined to local execution.
OpenCVE Enrichment