pentest api-security vault appsec
Vault API — Findings
Confirmed and candidate findings only. Theoretical test ideas belong in Vault API - Test Cases, not here.
How to Use
- Promote an issue here only after observing reproducible behavior.
- Log raw testing notes in Vault API - Evidence Log first.
- Tag GEL gate impact where applicable → GEL - Security Model > Security Gates.
Finding Template
Copy for each new finding:
Finding Name
Status: Candidate / Confirmed / Retest Passed / Retest Failed
Severity:
Category:
Endpoint:
Environment:
Identity:
Team Context:
Description
Preconditions
Steps / Evidence
Observed Behavior
Expected Behavior
Impact
Remediation
Retest
GEL Gate Candidate
Findings
No findings recorded yet.