CloudFront
tcp/443 tcp/80
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e208a11888215c6dac8808add1a2a429196ed1a0c1
GraphQL introspection enabled at /graphql/api Types: 397 (by kind: ENUM: 41, INPUT_OBJECT: 86, INTERFACE: 24, OBJECT: 241, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToWishlist Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa333455283a670b1814653cc6cb3140bcc7516d14e
GraphQL introspection enabled at /graphql Types: 437 (by kind: ENUM: 43, INPUT_OBJECT: 99, INTERFACE: 25, OBJECT: 265, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToWishlist Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa333455283a670b1814653cc6cb3140bcc7516d14e
GraphQL introspection enabled at /graphql Types: 437 (by kind: ENUM: 43, INPUT_OBJECT: 99, INTERFACE: 25, OBJECT: 265, SCALAR: 5) Operations: - Query: Query | fields: attributesForm, attributesList, availableStores, cart, categories - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addProductsToCart, addProductsToWishlist Directives: deprecated, include, oneOf, skip (total: 4)
Open service 18.66.192.6:80 · nyc-bloom.com
2025-12-22 08:53
HTTP/1.1 403 Forbidden Server: CloudFront Date: Mon, 22 Dec 2025 08:53:06 GMT Content-Type: text/html Content-Length: 919 Connection: close X-Cache: Error from cloudfront Via: 1.1 fb542039f97bb702c0e68d2142c449aa.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: wk1A_YZWcoCG_r6UhwI0fV3wDe6-byRt-GQidFq7MrQfEnONM-nXAw== Page title: ERROR: The request could not be satisfied <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1"> <TITLE>ERROR: The request could not be satisfied</TITLE> </HEAD><BODY> <H1>403 ERROR</H1> <H2>The request could not be satisfied.</H2> <HR noshade size="1px"> Request blocked. We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner. <BR clear="all"> If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation. <BR clear="all"> <HR noshade size="1px"> <PRE> Generated by cloudfront (CloudFront) Request ID: wk1A_YZWcoCG_r6UhwI0fV3wDe6-byRt-GQidFq7MrQfEnONM-nXAw== </PRE> <ADDRESS> </ADDRESS> </BODY></HTML>
Open service 18.66.192.6:443 · nyc-bloom.com
2025-12-22 06:48
HTTP/1.1 403 Forbidden Server: CloudFront Date: Mon, 22 Dec 2025 06:48:21 GMT Content-Type: text/html Content-Length: 919 Connection: close X-Cache: Error from cloudfront Via: 1.1 ba2af690a81a9d904af393a857344bf4.cloudfront.net (CloudFront) X-Amz-Cf-Pop: MUC50-P1 X-Amz-Cf-Id: ZovhC8LmMpI6piMElfqLsgmmBAibkLRlB2KonSl0Nry7pCTm80rHnw== Page title: ERROR: The request could not be satisfied <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd"> <HTML><HEAD><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1"> <TITLE>ERROR: The request could not be satisfied</TITLE> </HEAD><BODY> <H1>403 ERROR</H1> <H2>The request could not be satisfied.</H2> <HR noshade size="1px"> Request blocked. We can't connect to the server for this app or website at this time. There might be too much traffic or a configuration error. Try again later, or contact the app or website owner. <BR clear="all"> If you provide content to customers through CloudFront, you can find steps to troubleshoot and help prevent this error by reviewing the CloudFront documentation. <BR clear="all"> <HR noshade size="1px"> <PRE> Generated by cloudfront (CloudFront) Request ID: ZovhC8LmMpI6piMElfqLsgmmBAibkLRlB2KonSl0Nry7pCTm80rHnw== </PRE> <ADDRESS> </ADDRESS> </BODY></HTML>