{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "347af3aa3c473367731c02f1254a992680a69eef45ee728a8eb5ce846a36c856",
    "authored_runtime_manifest_sha256": "2564b10e934f1438239cb764feb9d79393e6a2c1e8f1f57b95d132ca6fdb9176",
    "authored_verdict_sha256": "6854ca3ee90c5d57b1e516b40d169016cc30cbd5d9f9deef1f981e4302a5cdf0",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "attacker_controlled_input": "An attacker-known anonymous Jenkins JSESSIONID planted in the victim browser before remember-me auto-login",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "authz_bypass",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "authz_bypass",
  "read_write_primitive_observed": false,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "HTTP login creates a remember-me token; a later request with that token and the planted JSESSIONID reaches RememberMeAuthenticationFilter; attacker replays only the planted JSESSIONID to /me/api/json",
  "validated_surface": "api_remote"
}
