Heroku
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3f85aa9c30421b6414e500e137b64383b7b64383b
GraphQL introspection enabled at /graphql Types: 20 (by kind: ENUM: 2, OBJECT: 14, SCALAR: 4) Operations: - Query: Query | fields: addLabToCompany, getCliengoCompanysTriggers, getCliengoIAReports, getMetrics, migrateLeadToCocos Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3f85aa9c30421b6414e500e137b64383b7b64383b
GraphQL introspection enabled at /graphql Types: 20 (by kind: ENUM: 2, OBJECT: 14, SCALAR: 4) Operations: - Query: Query | fields: addLabToCompany, getCliengoCompanysTriggers, getCliengoIAReports, getMetrics, migrateLeadToCocos Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Open service 3.33.241.96:80 · geniol.stagecliengo.com
2026-01-09 19:59
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 20:00:43 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=c1HdVuXqlBczfOQJ3Qug3xoe2MCpkn66WinibnpUoso%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767988843"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=c1HdVuXqlBczfOQJ3Qug3xoe2MCpkn66WinibnpUoso%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767988843"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}
Open service 76.223.57.73:443 · geniol.stagecliengo.com
2026-01-09 11:47
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Fri, 09 Jan 2026 11:47:22 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=abbhJoQa77g%2BY6X2MvHQj4Bvo3veOMtzROZdfPqx6Ak%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767959242"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=abbhJoQa77g%2BY6X2MvHQj4Bvo3veOMtzROZdfPqx6Ak%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767959242"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}
Open service 3.33.241.96:80 · geniol.stagecliengo.com
2026-01-02 17:59
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 17:59:54 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KrLREOLTDKbKA1namSVV6t27f%2BrsASUtFb3bTfxrf7E%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767376794"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KrLREOLTDKbKA1namSVV6t27f%2BrsASUtFb3bTfxrf7E%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767376794"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}
Open service 76.223.57.73:443 · geniol.stagecliengo.com
2026-01-02 16:30
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Fri, 02 Jan 2026 16:30:37 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=LmS3KY0%2FwfBfn70SoL72eDJ5KBDLcrTriy2pkeC0qCs%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767371437"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=LmS3KY0%2FwfBfn70SoL72eDJ5KBDLcrTriy2pkeC0qCs%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767371437"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}
Open service 76.223.57.73:443 · geniol.stagecliengo.com
2025-12-23 02:12
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Tue, 23 Dec 2025 02:12:49 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=fbrCZAGUKU%2FmVynLOt4uolcfFqjBStYc2cp%2BhQP3%2F2o%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766455969"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=fbrCZAGUKU%2FmVynLOt4uolcfFqjBStYc2cp%2BhQP3%2F2o%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766455969"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}
Open service 3.33.241.96:80 · geniol.stagecliengo.com
2025-12-22 16:20
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Mon, 22 Dec 2025 16:20:10 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=j%2FmJzTpFxV7X2YKak6%2BOwtzz5pstYIxKwkZPqKbP7js%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766420410"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=j%2FmJzTpFxV7X2YKak6%2BOwtzz5pstYIxKwkZPqKbP7js%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766420410"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}
Open service 76.223.57.73:443 · geniol.stagecliengo.com
2025-12-21 08:35
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Sun, 21 Dec 2025 08:35:58 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=AgQoaK6wGbIngc8sHTtawVLG5%2BzOMaAR5ymw%2FBRBOTI%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766306158"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=AgQoaK6wGbIngc8sHTtawVLG5%2BzOMaAR5ymw%2FBRBOTI%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766306158"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}
Open service 3.33.241.96:80 · geniol.stagecliengo.com
2025-12-20 18:44
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Sat, 20 Dec 2025 18:44:20 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=q97Q%2BQDV9ZEsMGB%2FY5BkD4K8ge3TudEKLZKuCzkVEp0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766256260"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=q97Q%2BQDV9ZEsMGB%2FY5BkD4K8ge3TudEKLZKuCzkVEp0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766256260"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}
Open service 76.223.57.73:443 · geniol.stagecliengo.com
2025-12-19 05:24
HTTP/1.1 400 Bad Request
Access-Control-Allow-Credentials: true
Cache-Control: no-store
Content-Length: 1096
Content-Type: application/json; charset=utf-8
Date: Fri, 19 Dec 2025 05:24:12 GMT
Etag: W/"448-Zqg9x3PLpHooJbfOhHDFhDnhP2w"
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=s9ZsaOlCiHiz90VNF4y%2BpLaHifP9EKXfxCnqY9Xsy0E%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766121852"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=s9ZsaOlCiHiz90VNF4y%2BpLaHifP9EKXfxCnqY9Xsy0E%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766121852"
Server: Heroku
Vary: Origin
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
{"errors":[{"message":"GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension.","extensions":{"code":"BAD_REQUEST","stacktrace":["BadRequestError: GraphQL operations must contain a non-empty `query` or a `persistedQuery` extension."," at new GraphQLErrorWithCode (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:10:9)"," at new BadRequestError (/app/node_modules/@apollo/server/dist/cjs/internalErrorClasses.js:84:9)"," at processGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/requestPipeline.js:71:13)"," at process.processTicksAndRejections (node:internal/process/task_queues:105:5)"," at async internalExecuteOperation (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:647:16)"," at async runHttpQuery (/app/node_modules/@apollo/server/dist/cjs/runHttpQuery.js:135:29)"," at async runPotentiallyBatchedHttpQuery (/app/node_modules/@apollo/server/dist/cjs/httpBatching.js:37:16)"," at async ApolloServer.executeHTTPGraphQLRequest (/app/node_modules/@apollo/server/dist/cjs/ApolloServer.js:557:20)"]}}]}