Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d72a48ac550906b0a79bc61d8a86000b404e298b
GraphQL introspection enabled at /graphql Types: 206 (by kind: ENUM: 37, INPUT_OBJECT: 43, INTERFACE: 23, OBJECT: 89, SCALAR: 10, UNION: 4) Operations: - Query: Query | fields: audiences, domains, event, events, feed - Mutation: Mutation | fields: activateOpportunity, activateRecord, archiveOpportunity, archiveRecord, createEvent Directives: deprecated, include, skip (total: 3)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d72a48ac550906b0a79bc61d8a86000b404e298b
GraphQL introspection enabled at /graphql Types: 206 (by kind: ENUM: 37, INPUT_OBJECT: 43, INTERFACE: 23, OBJECT: 89, SCALAR: 10, UNION: 4) Operations: - Query: Query | fields: audiences, domains, event, events, feed - Mutation: Mutation | fields: activateOpportunity, activateRecord, archiveOpportunity, archiveRecord, createEvent Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Open service 13.248.213.92:80 · api.uat.pathfinder.dfhcc.org
2026-01-09 14:20
HTTP/1.1 204 No Content
Cache-Control: no-cache
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ocID2AOsBnq1cb0N6jTtUMk7fpDkGETca3l8qLxitb8%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767968469"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ocID2AOsBnq1cb0N6jTtUMk7fpDkGETca3l8qLxitb8%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767968469"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 1763d61d-9114-1b8c-1049-36bfc3d021b6
X-Runtime: 0.036056
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 14:21:09 GMT
Connection: close
Open service 15.197.149.68:443 · api.uat.pathfinder.dfhcc.org
2026-01-09 05:52
HTTP/1.1 204 No Content
Cache-Control: no-cache
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=r3CBpq%2BF2FmnSr%2BYvnRQy%2B1%2FBNQG%2Fd7zd1%2BfKuR7%2BQE%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767937931"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=r3CBpq%2BF2FmnSr%2BYvnRQy%2B1%2FBNQG%2Fd7zd1%2BfKuR7%2BQE%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767937931"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 202969ca-e134-d356-d4c3-4d0bf1f830dc
X-Runtime: 0.097889
X-Xss-Protection: 0
Date: Fri, 09 Jan 2026 05:52:11 GMT
Connection: close
Open service 13.248.213.92:80 · api.uat.pathfinder.dfhcc.org
2026-01-02 15:15
HTTP/1.1 204 No Content
Cache-Control: no-cache
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KIxDn3B90NeczGdWD8RPgRy22TqFkPH7VJeu%2BHsxUZA%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767366930"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KIxDn3B90NeczGdWD8RPgRy22TqFkPH7VJeu%2BHsxUZA%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767366930"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 40d0d66e-48d9-98e5-b966-a2bf2d7a5774
X-Runtime: 0.001779
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 15:15:30 GMT
Connection: close
Open service 15.197.149.68:443 · api.uat.pathfinder.dfhcc.org
2026-01-02 10:59
HTTP/1.1 204 No Content
Cache-Control: no-cache
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=TwtLWMr4NfB1I3%2BUpmfStwrNPHolzLYqn5UISbpw4AI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767351575"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=TwtLWMr4NfB1I3%2BUpmfStwrNPHolzLYqn5UISbpw4AI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767351575"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 89e23d8a-4cf3-1336-2f92-730b170d192a
X-Runtime: 0.052898
X-Xss-Protection: 0
Date: Fri, 02 Jan 2026 10:59:35 GMT
Connection: close
Open service 13.248.213.92:80 · api.uat.pathfinder.dfhcc.org
2025-12-23 07:40
HTTP/1.1 204 No Content
Cache-Control: no-cache
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=9cIRvASsj03wgoGXV9JuRTudHUg%2BH5U%2BVNyjOMW6Z2Q%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766475620"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=9cIRvASsj03wgoGXV9JuRTudHUg%2BH5U%2BVNyjOMW6Z2Q%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766475620"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 384dad62-6924-62a4-ddd3-1bc005c0ce01
X-Runtime: 0.005878
X-Xss-Protection: 0
Date: Tue, 23 Dec 2025 07:40:20 GMT
Connection: close
Open service 15.197.149.68:443 · api.uat.pathfinder.dfhcc.org
2025-12-22 19:11
HTTP/1.1 204 No Content
Cache-Control: no-cache
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=EOYqShkbTQ10nZq9YGoU%2B6Vfc64sQX%2Br6WaDb3W0ZFQ%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766430695"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=EOYqShkbTQ10nZq9YGoU%2B6Vfc64sQX%2Br6WaDb3W0ZFQ%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766430695"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 37ba9f92-f9a1-d7e3-d812-2edfcdf80274
X-Runtime: 1.288247
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 19:11:36 GMT
Connection: close
Open service 13.248.213.92:80 · api.uat.pathfinder.dfhcc.org
2025-12-20 23:24
HTTP/1.1 204 No Content
Cache-Control: no-cache
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=JqnPCmclQqyKKxN2g4a9Gao%2BYysWCj6Ns0Rj4wc8R1c%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766273061"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=JqnPCmclQqyKKxN2g4a9Gao%2BYysWCj6Ns0Rj4wc8R1c%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766273061"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 4813c9bc-f382-179b-e2b7-dbc2049a4830
X-Runtime: 0.015488
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 23:24:21 GMT
Connection: close
Open service 15.197.149.68:443 · api.uat.pathfinder.dfhcc.org
2025-12-20 20:38
HTTP/1.1 204 No Content
Cache-Control: no-cache
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=MeEsRl%2FicJGsQqnn7pKL2w1b%2FX1dEBdCMsKa5wkPUk4%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766263095"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=MeEsRl%2FicJGsQqnn7pKL2w1b%2FX1dEBdCMsKa5wkPUk4%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766263095"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: f8d24d3f-2fd3-1d8e-697b-80a350f7e3cf
X-Runtime: 0.001591
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 20:38:15 GMT
Connection: close