{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "331e857be340df73d76d025862583e9849499bc9fbddbe05247c1affaeb4ab44",
    "authored_runtime_manifest_sha256": "75c9b2ecc338b78d06374426539feb9439bf9a1c32e2b804af4183dd9e9e42ae",
    "authored_verdict_sha256": "ddc73cf015b9c21b591ccfd1d763cde95534273b7d50d979d88b9cd93aae41b0",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "Unauthenticated HS256 join JWT (service_id/node_id claims chosen by attacker) signed with the publicly derivable blank-join-key HMAC secret (32 bytes of 0x20), sent to POST /access/api/v1/registry/join",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "authz_bypass",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "authz_bypass",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "JFrog Access RegistryNoAuthResource POST /access/api/v1/registry/join -> JoinServiceImpl.getValidatedJwtToken -> JoinKeyAccess.getTokenSignatureVerifiers (blank additional join key, kid=sha256('')) -> ServiceTokenProviderImpl issues scope=admin service token; then /access/api/v1/users + /access/api/v1/tokens + /artifactory/api/system/info for admin takeover",
  "validated_surface": "api_remote"
}
