pentest api-security vault appsec

Vault API — Findings

Confirmed and candidate findings only. Theoretical test ideas belong in Vault API - Test Cases, not here.


How to Use

  1. Promote an issue here only after observing reproducible behavior.
  2. Log raw testing notes in Vault API - Evidence Log first.
  3. Tag GEL gate impact where applicable → GEL - Security Model > Security Gates.

Finding Template

Copy for each new finding:

Finding Name

Status: Candidate / Confirmed / Retest Passed / Retest Failed
Severity:
Category:
Endpoint:
Environment:
Identity:
Team Context:

Description

Preconditions

Steps / Evidence

Observed Behavior

Expected Behavior

Impact

Remediation

Retest

GEL Gate Candidate


Findings

No findings recorded yet.