Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa355600455726f4a173239e8c344071dc796958ffb
GraphQL introspection enabled at /graphql Types: 81 (by kind: ENUM: 3, OBJECT: 69, SCALAR: 8, UNION: 1) Operations: - Query: Query | fields: curriculum, curriculumModule, lastSegment, lesson, user - Mutation: Mutation | fields: createMessageThread, createNextSegment, reportCompleteSubmission, reportExerciseProgress, reportProgress Directives: deprecated, include, skip, specifiedBy (total: 4)
Open service 75.2.60.68:443 · api.guitarmasteryintensive.com
2026-01-10 00:45
HTTP/1.1 404 Not Found
Content-Length: 179
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 10 Jan 2026 00:45:25 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=HfMUV5T05hvSDnZ9sFX2LIzf48BSSH8gE9xbu%2B%2FNyyI%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768005925"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=HfMUV5T05hvSDnZ9sFX2LIzf48BSSH8gE9xbu%2B%2FNyyI%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768005925"
Server: Heroku
Strict-Transport-Security: max-age=60; includeSubDomains; preload
Vary: origin, Cookie
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Connection: close
Page title: Not Found
<!doctype html>
<html lang="en">
<head>
<title>Not Found</title>
</head>
<body>
<h1>Not Found</h1><p>The requested resource was not found on this server.</p>
</body>
</html>
Open service 13.248.244.96:80 · api.guitarmasteryintensive.com
2026-01-10 00:45
HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 10 Jan 2026 00:46:27 GMT
Location: https://api.guitarmasteryintensive.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=V1Z%2BaSV8SG4vFGIzQbvHw1bSgGC53fzjeP3m3qFMH%2BY%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768005987"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=V1Z%2BaSV8SG4vFGIzQbvHw1bSgGC53fzjeP3m3qFMH%2BY%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768005987"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
Content-Length: 0
Connection: close
Open service 75.2.60.68:80 · api.guitarmasteryintensive.com
2026-01-10 00:45
HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 10 Jan 2026 00:46:27 GMT
Location: https://api.guitarmasteryintensive.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=V1Z%2BaSV8SG4vFGIzQbvHw1bSgGC53fzjeP3m3qFMH%2BY%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768005987"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=V1Z%2BaSV8SG4vFGIzQbvHw1bSgGC53fzjeP3m3qFMH%2BY%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768005987"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
Content-Length: 0
Connection: close
Open service 99.83.220.108:80 · api.guitarmasteryintensive.com
2026-01-10 00:45
HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 10 Jan 2026 00:46:26 GMT
Location: https://api.guitarmasteryintensive.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cCGGJz7GxxIG1ezHr2nFQCga8kzq1vpL6mMyZuh9wCE%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768005986"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cCGGJz7GxxIG1ezHr2nFQCga8kzq1vpL6mMyZuh9wCE%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768005986"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
Content-Length: 0
Connection: close
Open service 35.71.179.82:443 · api.guitarmasteryintensive.com
2026-01-10 00:45
HTTP/1.1 404 Not Found
Content-Length: 179
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 10 Jan 2026 00:45:25 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=HfMUV5T05hvSDnZ9sFX2LIzf48BSSH8gE9xbu%2B%2FNyyI%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768005925"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=HfMUV5T05hvSDnZ9sFX2LIzf48BSSH8gE9xbu%2B%2FNyyI%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768005925"
Server: Heroku
Strict-Transport-Security: max-age=60; includeSubDomains; preload
Vary: origin, Cookie
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Connection: close
Page title: Not Found
<!doctype html>
<html lang="en">
<head>
<title>Not Found</title>
</head>
<body>
<h1>Not Found</h1><p>The requested resource was not found on this server.</p>
</body>
</html>
Open service 13.248.244.96:443 · api.guitarmasteryintensive.com
2026-01-10 00:45
HTTP/1.1 404 Not Found
Content-Length: 179
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 10 Jan 2026 00:45:26 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=D5r%2BaxVmlcWF8Mi3%2B5Ud2LCAJkx3LhWonseBLwwZSjs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768005926"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=D5r%2BaxVmlcWF8Mi3%2B5Ud2LCAJkx3LhWonseBLwwZSjs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768005926"
Server: Heroku
Strict-Transport-Security: max-age=60; includeSubDomains; preload
Vary: origin, Cookie
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Connection: close
Page title: Not Found
<!doctype html>
<html lang="en">
<head>
<title>Not Found</title>
</head>
<body>
<h1>Not Found</h1><p>The requested resource was not found on this server.</p>
</body>
</html>
Open service 99.83.220.108:443 · api.guitarmasteryintensive.com
2026-01-10 00:45
HTTP/1.1 404 Not Found
Content-Length: 179
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 10 Jan 2026 00:45:26 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=D5r%2BaxVmlcWF8Mi3%2B5Ud2LCAJkx3LhWonseBLwwZSjs%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768005926"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=D5r%2BaxVmlcWF8Mi3%2B5Ud2LCAJkx3LhWonseBLwwZSjs%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768005926"
Server: Heroku
Strict-Transport-Security: max-age=60; includeSubDomains; preload
Vary: origin, Cookie
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Connection: close
Page title: Not Found
<!doctype html>
<html lang="en">
<head>
<title>Not Found</title>
</head>
<body>
<h1>Not Found</h1><p>The requested resource was not found on this server.</p>
</body>
</html>
Open service 35.71.179.82:80 · api.guitarmasteryintensive.com
2026-01-10 00:45
HTTP/1.1 301 Moved Permanently
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 10 Jan 2026 00:46:26 GMT
Location: https://api.guitarmasteryintensive.com/
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=cCGGJz7GxxIG1ezHr2nFQCga8kzq1vpL6mMyZuh9wCE%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1768005986"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=cCGGJz7GxxIG1ezHr2nFQCga8kzq1vpL6mMyZuh9wCE%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1768005986"
Server: Heroku
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
Content-Length: 0
Connection: close
Open service 75.2.60.68:443 · api.guitarmasteryintensive.com
2026-01-09 11:44
HTTP/1.1 404 Not Found
Content-Length: 179
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Fri, 09 Jan 2026 11:44:55 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=%2Bpmxtk4FuHJ7EYuJ%2F7lQ%2FROrkmH8C0Twi1g3UulWai4%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767959095"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=%2Bpmxtk4FuHJ7EYuJ%2F7lQ%2FROrkmH8C0Twi1g3UulWai4%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767959095"
Server: Heroku
Strict-Transport-Security: max-age=60; includeSubDomains; preload
Vary: origin, Cookie
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Connection: close
Page title: Not Found
<!doctype html>
<html lang="en">
<head>
<title>Not Found</title>
</head>
<body>
<h1>Not Found</h1><p>The requested resource was not found on this server.</p>
</body>
</html>
Open service 75.2.60.68:443 · api.guitarmasteryintensive.com
2026-01-02 03:01
HTTP/1.1 404 Not Found
Content-Length: 179
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Fri, 02 Jan 2026 03:01:38 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=w7M5xuSZH6aa4O8DGKArodeGnTjXv2FVviRDWSjOqPE%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767322898"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=w7M5xuSZH6aa4O8DGKArodeGnTjXv2FVviRDWSjOqPE%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767322898"
Server: Heroku
Strict-Transport-Security: max-age=60; includeSubDomains; preload
Vary: origin, Cookie
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Connection: close
Page title: Not Found
<!doctype html>
<html lang="en">
<head>
<title>Not Found</title>
</head>
<body>
<h1>Not Found</h1><p>The requested resource was not found on this server.</p>
</body>
</html>
Open service 75.2.60.68:443 · api.guitarmasteryintensive.com
2025-12-22 18:41
HTTP/1.1 404 Not Found
Content-Length: 179
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Mon, 22 Dec 2025 18:41:10 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=DNk%2FOOUgwGYBI5NDeqRgAyqJ5Cc4Oq6IiYesqvcVUZI%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766428870"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=DNk%2FOOUgwGYBI5NDeqRgAyqJ5Cc4Oq6IiYesqvcVUZI%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766428870"
Server: Heroku
Strict-Transport-Security: max-age=60; includeSubDomains; preload
Vary: origin, Cookie
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Connection: close
Page title: Not Found
<!doctype html>
<html lang="en">
<head>
<title>Not Found</title>
</head>
<body>
<h1>Not Found</h1><p>The requested resource was not found on this server.</p>
</body>
</html>
Open service 75.2.60.68:443 · api.guitarmasteryintensive.com
2025-12-20 21:11
HTTP/1.1 404 Not Found
Content-Length: 179
Content-Type: text/html; charset=utf-8
Cross-Origin-Opener-Policy: same-origin
Date: Sat, 20 Dec 2025 21:11:59 GMT
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: same-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=LYWG2h8uw1gWrACTjtAi%2Fglv79YW974sznRSQBT8dgU%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766265119"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=LYWG2h8uw1gWrACTjtAi%2Fglv79YW974sznRSQBT8dgU%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766265119"
Server: Heroku
Strict-Transport-Security: max-age=60; includeSubDomains; preload
Vary: origin, Cookie
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Frame-Options: DENY
Connection: close
Page title: Not Found
<!doctype html>
<html lang="en">
<head>
<title>Not Found</title>
</head>
<body>
<h1>Not Found</h1><p>The requested resource was not found on this server.</p>
</body>
</html>