{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "217a383f8df3f819a88bc29129d496a5500d3dc4359facb7d575664e103dcb80",
    "authored_runtime_manifest_sha256": "015f53127d4b3e2d6f3e2a0c341a79030b5cf402786d1dc3384a15d923822aa1",
    "authored_verdict_sha256": "00e086b858c394310ef1548be5a49e994f2835267f6290da4e9adff3a36cd675",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "url_token path parameter of an unauthenticated DELETE /p/<url_token>.json request",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "authz_bypass",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": false,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "authz_bypass",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "Api::V1::PushesController#destroy (and PushesController#expire for HTML) via (@push.user == current_user) || @push.deletable_by_viewer where nil == nil",
  "validated_surface": "api_remote"
}
