Apache
tcp/443
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: high
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652232591c12
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://HeraDevSecOps@dev.azure.com/HeraDevSecOps/VDB%202022_1B16%20-%20Porting%20servizio%20PaaS%20Wordpress/_git/digielodegrh fetch = +refs/heads/*:refs/remotes/origin/* [branch "main"] remote = origin merge = refs/heads/main
Open service 13.33.187.82:443 ยท digielode.gruppohera.it
2026-01-23 03:13
HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Transfer-Encoding: chunked Connection: close Date: Fri, 23 Jan 2026 03:13:59 GMT Server-Timing: dtSInfo;desc="0", dtRpid;desc="1991700285" Set-Cookie: dtCookie4bzigacw=v_4_srv_2_sn_25EF4DDA867DFFE11D22B13F9EFC1EBF_perc_100000_ol_0_mul_1_app-3Aa1c15d961e14c001_1; Path=/; Domain=.gruppohera.it Server: Apache Cache-Control: no-cache, no-store, must-revalidate Link: <https://digielode.gruppohera.it/wp-json/>; rel="https://api.w.org/" X-Frame-Options: DENY Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-OneAgent-JS-Injection: true X-ruxit-JS-Agent: true X-Cache: Miss from cloudfront Via: 1.1 abf16b943a9b4039b87ccdb094d9303e.cloudfront.net (CloudFront) X-Amz-Cf-Pop: FRA60-P9 X-Amz-Cf-Id: bfTkILxIlIHvkTZujkL8eLIVt4lseFH06YDfkU2EsCCfJva_n724dQ==