{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "9cacd64df31f43820e0342f58bba16d4d6b0de496373344b181156410b45da60",
    "authored_runtime_manifest_sha256": "298aeaa03a70e673a129a2cc00623dc769de1a55c52c2d726531f1b69f0cf556",
    "authored_verdict_sha256": "8e336bc9a1c5128be2de5562e64306eeb1ebac41f63d7fb76e0d3d7b44e0944b",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "unauthenticated HTTP requests: POST tryAnotherWay=on, POST username=<victim>, GET refresh of the reset-credentials execution URL, POST to the leaked reset-credential-email execution URL (no action token), POST attacker-chosen password",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "authz_bypass",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "authz_bypass",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "GET/POST /realms/cvetest/login-actions/reset-credentials (Keycloak reset-credentials flow; ResetCredentialEmail execution)",
  "validated_surface": "api_remote"
}
