{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "60897bb2292f582322e47328edf165a61b3988517ae150c8fb7cae35aa3f35ec",
    "authored_runtime_manifest_sha256": "c92ae339c8e6c31c4ef7e235eaf675c740b9a95dc2078f3172d57fa921a47500",
    "authored_verdict_sha256": "608734266a874aaa630488aaf6e50444a59cf772bae259ed76a51d40e68e2b20",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "4bffb2ed-350e-4937-aed0-0ae82dc940e6"
  ],
  "attacker_controlled_input": "A same-site sibling-host HTML page that includes the Jenkins /$stapler/bound/script endpoint, captures its crumb argument, and submits it in a cross-origin form",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "authz_bypass",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "authz_bypass",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "Chromium victim login -> attacker.example.test page -> GET /$stapler/bound/script/whatever -> forged POST /me/descriptorByName/jenkins.security.ApiTokenProperty/generateNewToken",
  "validated_surface": "api_remote"
}
