cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3eb804dadb633a90f819d92780e210614215b3af4
GraphQL introspection enabled at /graphql Types: 319 (by kind: ENUM: 30, INPUT_OBJECT: 122, INTERFACE: 9, OBJECT: 151, SCALAR: 7) Operations: - Query: Query | fields: assertGroupByCode, canRemoveMemberOfGroup, cartMeta, cartsMeta, checkCatalogCatchmentArea - Mutation: Mutation | fields: acceptInvitation, activateFutureSales, activateProducts, addFavoriteCatalog, addGroupAddress Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3eb804dadb633a90f3a0b5640c7ebe41cd81ce36c
GraphQL introspection enabled at /graphql Types: 319 (by kind: ENUM: 30, INPUT_OBJECT: 122, INTERFACE: 9, OBJECT: 151, SCALAR: 7) Operations: - Query: Query | fields: assertGroupByCode, cartMeta, cartsMeta, checkCatalogCatchmentArea, checkEmail - Mutation: Mutation | fields: acceptInvitation, activateFutureSales, activateProducts, addFavoriteCatalog, addGroupAddress Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa39f48870a11625cba67c1543d3d958f77ee630fcf
GraphQL introspection enabled at /graphql Types: 310 (by kind: ENUM: 30, INPUT_OBJECT: 120, INTERFACE: 9, OBJECT: 144, SCALAR: 7) Operations: - Query: Query | fields: assertGroupByCode, cartMeta, cartsMeta, checkCatalogCatchmentArea, checkEmail - Mutation: Mutation | fields: activateFutureSales, activateProducts, addFavoriteCatalog, addGroupAddress, addMemberToGroup Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3614601224f75be72fd091aa549a0aabfb348c067
GraphQL introspection enabled at /graphql Types: 312 (by kind: ENUM: 30, INPUT_OBJECT: 120, INTERFACE: 9, OBJECT: 146, SCALAR: 7) Operations: - Query: Query | fields: assertGroupByCode, cartMeta, cartsMeta, checkCatalogCatchmentArea, checkEmail - Mutation: Mutation | fields: activateFutureSales, activateProducts, addFavoriteCatalog, addGroupAddress, addMemberToGroup Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa36fed4af9f06d829b80df1bdfa4d25411248da62d
GraphQL introspection enabled at /graphql Types: 313 (by kind: ENUM: 37, INPUT_OBJECT: 116, INTERFACE: 9, OBJECT: 144, SCALAR: 7) Operations: - Query: Query | fields: cartMeta, cartsMeta, checkCatalogCatchmentArea, checkEmail, deleteCartComponent - Mutation: Mutation | fields: activateFutureSales, activateProducts, addFavoriteCatalog, addGroupAddress, addMemberToGroup Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa33fecb65f08618f6df511c715c55ae3d80add73f8
GraphQL introspection enabled at /graphql Types: 310 (by kind: ENUM: 36, INPUT_OBJECT: 115, INTERFACE: 9, OBJECT: 143, SCALAR: 7) Operations: - Query: Query | fields: cartMeta, cartsMeta, checkCatalogCatchmentArea, checkEmail, deleteCartComponent - Mutation: Mutation | fields: activateProducts, addFavoriteCatalog, addGroupAddress, addMemberToGroup, anonymizeAccount Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa367df46ff3fe5afcdc04c0759ea2b6514dcd389f4
GraphQL introspection enabled at /graphql Types: 264 (by kind: ENUM: 36, INPUT_OBJECT: 100, INTERFACE: 9, OBJECT: 112, SCALAR: 7) Operations: - Query: Query | fields: checkCatalogCatchmentArea, checkEmail, deleteCartComponent, findCarts, findCatalogs - Mutation: Mutation | fields: activateProducts, addFavoriteCatalog, addGroupAddress, addMemberToGroup, anonymizeAccount Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 172.67.71.53:443 · api-preprod.gr.app
2026-01-09 17:26
HTTP/1.1 404 Not Found
Date: Fri, 09 Jan 2026 17:26:38 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 134
Connection: close
content-security-policy: script-src 'self' https: 'unsafe-inline' 'unsafe-eval';frame-ancestors https://preprod.gr.app;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';img-src 'self' data:;object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
etag: W/"86-T2OTbT2z7BAcgT4RUPBp9ogyLOI"
origin-agent-cluster: ?1
referrer-policy: no-referrer
strict-transport-security: max-age=15552000; includeSubDomains
vary: Origin
via: 1.1 Caddy
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=1RJV6qAgUzSVFdVXthzr4J7dzTj46bePMc9rXhUJI9safnhyeVKYH0eAcfTrAQumSoo%2Fds%2BiwktVuQ21hu3H262aT5PWDEUEGiNgsPYUJfYO"}]}
Server: cloudflare
CF-RAY: 9bb5a40a3f5fa8da-SIN
{"status":404,"exception":"NOT_FOUND","code":"UNKNOWN","message":"Cannot GET /","path":"GET /","timestamp":"2026-01-09T17:26:38.607Z"}
Open service 172.67.71.53:443 · api-preprod.gr.app
2026-01-02 09:02
HTTP/1.1 404 Not Found
Date: Fri, 02 Jan 2026 09:02:28 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 134
Connection: close
content-security-policy: script-src 'self' https: 'unsafe-inline' 'unsafe-eval';frame-ancestors https://preprod.gr.app;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';img-src 'self' data:;object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
etag: W/"86-a2cBiV5jUKKxUdlzBLUwnA+95+o"
origin-agent-cluster: ?1
referrer-policy: no-referrer
strict-transport-security: max-age=15552000; includeSubDomains
vary: Origin
via: 1.1 Caddy
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=npDUvBQF5Df%2FbgAvofXyb2Q6RRx4lwnT7gNXYz3IKf0b2d0KDj3XcAnr%2FBTx8fu05VtypvGz9hCmCFkgYyLf5lyz1OXc7hCKdFQjnfmV51LD"}]}
Server: cloudflare
CF-RAY: 9b7913e37b5fcb77-BLR
{"status":404,"exception":"NOT_FOUND","code":"UNKNOWN","message":"Cannot GET /","path":"GET /","timestamp":"2026-01-02T09:02:28.505Z"}
Open service 172.67.71.53:443 · api-preprod.gr.app
2025-12-22 21:19
HTTP/1.1 404 Not Found
Date: Mon, 22 Dec 2025 21:19:20 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 134
Connection: close
content-security-policy: script-src 'self' https: 'unsafe-inline' 'unsafe-eval';frame-ancestors https://preprod.gr.app;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';img-src 'self' data:;object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
etag: W/"86-Jy6iPJdkQvxg+ZZ9H0ATJPlprcA"
origin-agent-cluster: ?1
referrer-policy: no-referrer
strict-transport-security: max-age=15552000; includeSubDomains
vary: Origin
via: 1.1 Caddy
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=NDpn1Y46OluREyEBWbboqoCKpao4kbeWZOmM2%2F1QD680pCx4sjRlvqpGvks1jfiIm3rcfS1vpznSzoX8c9Pw%2B9B9htvQjwuVt2nAjvfyB3Sq"}]}
Server: cloudflare
CF-RAY: 9b22a8263e499bfe-FRA
{"status":404,"exception":"NOT_FOUND","code":"UNKNOWN","message":"Cannot GET /","path":"GET /","timestamp":"2025-12-22T21:19:20.063Z"}
Open service 172.67.71.53:443 · api-preprod.gr.app
2025-12-20 23:02
HTTP/1.1 404 Not Found
Date: Sat, 20 Dec 2025 23:02:08 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 134
Connection: close
content-security-policy: script-src 'self' https: 'unsafe-inline' 'unsafe-eval';frame-ancestors https://preprod.gr.app;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';img-src 'self' data:;object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
etag: W/"86-gyA+6ze1lnXDvfYp0RsfOy+hdX4"
origin-agent-cluster: ?1
referrer-policy: no-referrer
strict-transport-security: max-age=15552000; includeSubDomains
vary: Origin
via: 1.1 Caddy
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=%2B%2FlGorD0URxHdd3sRfTdSxzf%2FGjVDMPA00moAt%2FVYvyFM%2FYChk0d5AQAIAEG5CltyfTaPbbd7lYdg4jFuqv%2BKl1wnRuIHRDcAD76LSzS3pB6"}]}
Server: cloudflare
CF-RAY: 9b12c3fae9c9f41f-YYZ
{"status":404,"exception":"NOT_FOUND","code":"UNKNOWN","message":"Cannot GET /","path":"GET /","timestamp":"2025-12-20T23:02:08.182Z"}
Open service 172.67.71.53:443 · api-preprod.gr.app
2025-12-19 01:47
HTTP/1.1 404 Not Found
Date: Fri, 19 Dec 2025 01:47:14 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 134
Connection: close
content-security-policy: script-src 'self' https: 'unsafe-inline' 'unsafe-eval';frame-ancestors https://preprod.gr.app;default-src 'self';base-uri 'self';font-src 'self' https: data:;form-action 'self';img-src 'self' data:;object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline';upgrade-insecure-requests
cross-origin-opener-policy: same-origin
cross-origin-resource-policy: same-origin
etag: W/"86-CnzmNWUoyTLimLlVuTcux64j/r0"
origin-agent-cluster: ?1
referrer-policy: no-referrer
strict-transport-security: max-age=15552000; includeSubDomains
vary: Origin
via: 1.1 Caddy
x-content-type-options: nosniff
x-dns-prefetch-control: off
x-download-options: noopen
x-frame-options: SAMEORIGIN
x-permitted-cross-domain-policies: none
x-xss-protection: 0
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=Z9%2F20UtIqZGKMB%2BEc0JpCfZTwRkzRygLTWu5Zw3WbUX5JeRYJrGno8hEQozs%2Bia29bZ4sHA183fpeLvKH7Raqa1YZSurJZHibs%2Fha696cq%2BS"}]}
Server: cloudflare
CF-RAY: 9b033b14ab41d9da-FRA
{"status":404,"exception":"NOT_FOUND","code":"UNKNOWN","message":"Cannot GET /","path":"GET /","timestamp":"2025-12-19T01:47:14.042Z"}