Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Open service 75.2.60.68:443 · bo.fleetpanda.com
2026-01-09 10:02
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://bo.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=xAFu6X9ifhJO29alqzpaUM8cS23WQCtLnjTb%2BKP3%2Fz0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767952933"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=xAFu6X9ifhJO29alqzpaUM8cS23WQCtLnjTb%2BKP3%2Fz0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767952933"
Server: Heroku
Set-Cookie: _fleetpanda_session=rtWDikV7ygnPL7Wiw2Gw1PRtiRgw5GTE%2BlE0YsSGDCHkM0U6gzswATVTk%2BLvQ8jN7E3FohnhX2g0o1cOmQF%2Feiet14mcDXU%2BjU496SKLsCSxkYLCgSfwbODzRmCf3ILejLa%2BnTJ0BijwQonNO%2F2pdZWTc7SYrVgZ3Gh1KmgBTfIFFbbZhuNx%2FKWFvefdv1xMWdL1vsvuiNSlSDmaqG6rzLUGaCMY--5nILciSjqSY72o4C--cyO0Vz4E81BZjNYt117uCQ%3D%3D; domain=.bo.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 513a0f7f-c3a5-d1bb-33b0-811132674e47
X-Runtime: 0.005623
Date: Fri, 09 Jan 2026 10:02:13 GMT
Content-Length: 103
Connection: close
<html><body>You are being <a href="https://bo.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 75.2.60.68:443 · bo.fleetpanda.com
2026-01-02 10:35
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://bo.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Ea%2FwlLWGcPsKqZL04m9qT3hknyDV8eLcnJ%2FWJ7X8MR4%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1767350143"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Ea%2FwlLWGcPsKqZL04m9qT3hknyDV8eLcnJ%2FWJ7X8MR4%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1767350143"
Server: Heroku
Set-Cookie: _fleetpanda_session=%2BVUKFvZ8ExvKWujRS2sGWh8TgnEDte%2Fkt80vCXKgJg%2F9zXa65zhsgPh4X%2BZAaGXVqDruzTUncSini%2B%2FDiW%2FhPZna6pM6pEIsxNovsdVe%2B8TiO4Zu08nnMn35Qx4nmz0aTjEuqCJLTV2S7kIz0XSYFERRyeW3V5lxPU%2BpBCzEE%2BO2XeoXfmPT9GxGaPHTQlhK2lRoNmwa6QReJ6pgLWizVoG0dwKI--%2FkYJS2msDIEjOvr1--vulDLNQ0%2Bgnx8RYagivBfg%3D%3D; domain=.bo.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 8398c397-2990-4078-f646-7b677f345f48
X-Runtime: 0.004351
Date: Fri, 02 Jan 2026 10:35:43 GMT
Content-Length: 103
Connection: close
<html><body>You are being <a href="https://bo.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 75.2.60.68:443 · bo.fleetpanda.com
2025-12-23 07:13
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://bo.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=yuI%2FgnbRpYR8YYN9h76N7Kv3rn2YjNB5Q6PftAWZ2B0%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766474021"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=yuI%2FgnbRpYR8YYN9h76N7Kv3rn2YjNB5Q6PftAWZ2B0%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766474021"
Server: Heroku
Set-Cookie: _fleetpanda_session=As4N42LtHwoROzqWrBPPJYamroenJjxBW%2BF9UVdRBBYpnNcwMETOy4gQVmsMmm50n8aQCXBrO3d49tEv8nY3UZXb6V98FmDyHpaQQkwHgB3g%2F9GqUSds1I7UNP91gA6quwyEnmzrHFvTslqQ2MgMheJer0czh5K9s009Qly1xgOtewfjmFxK%2FTsNUHRL5GkzWjfRvuBTi8Qos64U%2B5CnqYF94rdp--iB%2BVeM4qP9pvVvyO--h%2FM59oaFrlri%2BLTZJCljDA%3D%3D; domain=.bo.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: ac777ad8-d591-ac58-cd43-721c109d631f
X-Runtime: 0.016337
Date: Tue, 23 Dec 2025 07:13:41 GMT
Content-Length: 103
Connection: close
<html><body>You are being <a href="https://bo.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 75.2.60.68:443 · bo.fleetpanda.com
2025-12-21 06:00
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://bo.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=AdzrIHaNytGj4CSeDMxzx7QyzJ60x1lNxfyjgVdDEFw%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766296808"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=AdzrIHaNytGj4CSeDMxzx7QyzJ60x1lNxfyjgVdDEFw%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766296808"
Server: Heroku
Set-Cookie: _fleetpanda_session=cqLiD4yPOHQ%2F8VbesfbFNQ8i5oDfkP1pjsU%2FjGwlxppAx77J02mAXTVtvQKdj2hu5ebpnUfDDQP6xF9ZkqAxBphKKbRoBDEZyJ4qr3Gc1AcZ6EnSlUv8dJ3XMx1E8kAPGAorU1JW1Qnsn%2B5U9fRtVGGM8Ro4MZi5mYB46kPaw9e3NF8RLwfV6doSHTPOJyB92h4NKwh8je1g6qKodHPU1L3lDDDl--GEg3ApevUpXpwS8c--PJrvDy5jya7heE5AZ0GENw%3D%3D; domain=.bo.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 9bb43f1b-b3a3-bff1-36fd-439f50b22245
X-Runtime: 0.005341
Date: Sun, 21 Dec 2025 06:00:08 GMT
Content-Length: 103
Connection: close
<html><body>You are being <a href="https://bo.fleetpanda.com/users/login">redirected</a>.</body></html>
Open service 75.2.60.68:443 · bo.fleetpanda.com
2025-12-19 03:33
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Type: text/html; charset=utf-8
Location: https://bo.fleetpanda.com/users/login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=1sgI17TZxzwe%2BiRdnzDdWULZBoNnmttDqdt7kldjydA%3D\u0026sid=1b10b0ff-8a76-4548-befa-353fc6c6c045\u0026ts=1766115220"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=1sgI17TZxzwe%2BiRdnzDdWULZBoNnmttDqdt7kldjydA%3D&sid=1b10b0ff-8a76-4548-befa-353fc6c6c045&ts=1766115220"
Server: Heroku
Set-Cookie: _fleetpanda_session=pJ3ABELZEaTuTWmUW9Xz4fP40XQMQYXfB1Gw0XeRNQUq4GMfhf6Odt6GUO8GfNGPkq%2BfZKCeps4dR%2FtQtI8U62EtWhd0%2BQAd%2F2PMu1c3%2Foj355JtWRabrFHAeu3SeTRnZQqqQYMG%2FgA%2BveTBbNjoJbPDGdDwb1dsWOk%2FVqlLqWETtklxOfCcadpnAnOu0eIBPTak%2BWczTvmgbfRP3W6xaaHdeHnY--AAJOO86oJU01zWGB--aKWpxaXrZHOIjcjecOG7JQ%3D%3D; domain=.bo.fleetpanda.com; path=/; secure; HttpOnly; SameSite=Lax
Strict-Transport-Security: max-age=63072000; includeSubDomains
Vary: Origin
Via: 1.1 heroku-router
X-Request-Id: 06b9df79-5c1a-10eb-9f92-8e4481ecfb24
X-Runtime: 0.004544
Date: Fri, 19 Dec 2025 03:33:40 GMT
Content-Length: 103
Connection: close
<html><body>You are being <a href="https://bo.fleetpanda.com/users/login">redirected</a>.</body></html>