Varnish
tcp/443 tcp/80
nginx 1.29.2
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d65e6ca86ab49b8bda2e10490d283bd43d09054fda
GraphQL introspection enabled at /api/graphql Types: 1531 (by kind: ENUM: 176, INPUT_OBJECT: 288, INTERFACE: 23, OBJECT: 918, SCALAR: 119, UNION: 7) Operations: - Query: Query | fields: abuseReport, abuseReportLabels, auditEventDefinitions, boardList, ciApplicationSettings - Mutation: Mutation | fields: abuseReportLabelCreate, achievementsAward, achievementsCreate, achievementsDelete, achievementsRevoke - Subscription: Subscription | fields: ciPipelineStatusUpdated, issuableAssigneesUpdated, issuableDatesUpdated, issuableDescriptionUpdated, issuableLabelsUpdated Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e071d1534171d1534171d1534171d1534171d153417
Symfony profiler enabled: https://staging-taxonomy-api.prisamedia.com/_profiler/empty/search/results
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e07d2f889ced2f889ced2f889ced2f889ced2f889ce
Symfony profiler enabled: https://staging-taxonomy-core.prisamedia.com/_profiler/empty/search/results
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e073df6f3343df6f3343df6f3343df6f3343df6f334
Symfony profiler enabled: http://staging-taxonomy-api.prisamedia.com/_profiler/empty/search/results
The application has Symfony profiling enabled.
It enables an attacker to access the following sensitive content :
Fingerprint: 407cf4363b0e62fafca67e0714f1351b14f1351b14f1351b14f1351b14f1351b
Symfony profiler enabled: http://staging-taxonomy-core.prisamedia.com/_profiler/empty/search/results
Open service 68.221.89.1:443 · gestionriesgos-api.prisamedia.com
2026-02-13 03:12
HTTP/1.1 401 Unauthorized Content-Length: 58 Connection: close Content-Type: text/html Date: Fri, 13 Feb 2026 03:12:14 GMT WWW-Authenticate: Bearer realm="gestionriesgos-api.prisamedia.com" Strict-Transport-Security: max-age=31536000; includeSubDomains x-ms-middleware-request-id: c163f30f-751d-498b-8789-d4f2440029eb X-Powered-By: ASP.NET You do not have permission to view this directory or page.
Open service 199.232.198.133:443 · staging-taxonomy-core.prisamedia.com
2026-02-01 23:10
HTTP/1.1 500 Domain Not Found Connection: close Content-Length: 318 Server: Varnish Retry-After: 0 content-type: text/html Cache-Control: private, no-cache X-Served-By: cache-pao-kpao1770055-PAO Accept-Ranges: bytes Date: Sun, 01 Feb 2026 23:10:45 GMT Via: 1.1 varnish Page title: Fastly error: unknown domain staging-taxonomy-core.prisamedia.com <html> <head> <title>Fastly error: unknown domain staging-taxonomy-core.prisamedia.com</title> </head> <body> <p>Fastly error: unknown domain: staging-taxonomy-core.prisamedia.com. Please check that this domain has been added to a service.</p> <p>Details: cache-pao-kpao1770055-PAO (199.232.198.133)</p></body></html>
Open service 199.232.198.133:443 · int-entrypoint.soda.prisamedia.com
2026-01-23 21:20
HTTP/1.1 403 Forbidden
Connection: close
Content-Length: 425
Server: Varnish
Retry-After: 0
Content-Type: text/html; charset=utf-8
Accept-Ranges: bytes
Date: Fri, 23 Jan 2026 21:20:28 GMT
Via: 1.1 varnish
X-Served-By: cache-rtm-ehrd2290052-RTM
X-Cache: MISS
X-Cache-Hits: 0
X-Timer: S1769203228.164213,VS0,VE0
Page title: 403 Forbidden
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>403 Forbidden</title>
</head>
<body>
<h1>Error 403 Forbidden</h1>
<p>Forbidden</p>
<h3>Error 54113</h3>
<p>Details: cache-rtm-ehrd2290052-RTM 1769203228 1904134568</p>
<hr>
<p>Varnish cache server</p>
</body>
</html>
Open service 199.232.194.133:443 · int-entrypoint.soda.prisamedia.com
2026-01-23 21:20
HTTP/1.1 403 Forbidden
Connection: close
Content-Length: 425
Server: Varnish
Retry-After: 0
Content-Type: text/html; charset=utf-8
Accept-Ranges: bytes
Date: Fri, 23 Jan 2026 21:20:28 GMT
Via: 1.1 varnish
X-Served-By: cache-rtm-ehrd2290040-RTM
X-Cache: MISS
X-Cache-Hits: 0
X-Timer: S1769203228.088651,VS0,VE0
Page title: 403 Forbidden
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>403 Forbidden</title>
</head>
<body>
<h1>Error 403 Forbidden</h1>
<p>Forbidden</p>
<h3>Error 54113</h3>
<p>Details: cache-rtm-ehrd2290040-RTM 1769203228 3785185201</p>
<hr>
<p>Varnish cache server</p>
</body>
</html>
Open service 199.232.194.133:80 · int-entrypoint.soda.prisamedia.com
2026-01-23 21:20
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://int-entrypoint.soda.prisamedia.com/ Accept-Ranges: bytes Date: Fri, 23 Jan 2026 21:20:26 GMT Via: 1.1 varnish X-Served-By: cache-lcy-egml8630098-LCY X-Cache: HIT X-Cache-Hits: 0
Open service 199.232.198.133:80 · int-entrypoint.soda.prisamedia.com
2026-01-23 21:20
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://int-entrypoint.soda.prisamedia.com/ Accept-Ranges: bytes Date: Fri, 23 Jan 2026 21:20:26 GMT Via: 1.1 varnish X-Served-By: cache-vie6341-VIE X-Cache: HIT X-Cache-Hits: 0
Open service 199.232.198.133:443 · staging-taxonomy-api.prisamedia.com
2026-01-22 23:33
HTTP/1.1 403 Forbidden
Connection: close
Content-Length: 424
Server: Varnish
Retry-After: 0
Content-Type: text/html; charset=utf-8
Accept-Ranges: bytes
Date: Thu, 22 Jan 2026 23:33:52 GMT
Via: 1.1 varnish
X-Served-By: cache-fra-eddf8230172-FRA
X-Cache: MISS
X-Cache-Hits: 0
X-Timer: S1769124832.416688,VS0,VE0
Page title: 403 Forbidden
<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html>
<head>
<title>403 Forbidden</title>
</head>
<body>
<h1>Error 403 Forbidden</h1>
<p>Forbidden</p>
<h3>Error 54113</h3>
<p>Details: cache-fra-eddf8230172-FRA 1769124832 494701500</p>
<hr>
<p>Varnish cache server</p>
</body>
</html>
Open service 199.232.198.133:443 · staging-taxonomy-core.prisamedia.com
2026-01-22 22:19
HTTP/1.1 500 Domain Not Found Connection: close Content-Length: 311 Server: Varnish Retry-After: 0 content-type: text/html Cache-Control: private, no-cache X-Served-By: cache-lga21962-LGA Accept-Ranges: bytes Date: Thu, 22 Jan 2026 22:19:31 GMT Via: 1.1 varnish Page title: Fastly error: unknown domain staging-taxonomy-core.prisamedia.com <html> <head> <title>Fastly error: unknown domain staging-taxonomy-core.prisamedia.com</title> </head> <body> <p>Fastly error: unknown domain: staging-taxonomy-core.prisamedia.com. Please check that this domain has been added to a service.</p> <p>Details: cache-lga21962-LGA (199.232.198.133)</p></body></html>
Open service 199.232.198.133:443 · sltywh-ep.prisamedia.com
2026-01-12 16:40
HTTP/1.1 404 Not Found
Connection: close
Content-Length: 21
via: 1.1 google, 1.1 varnish, 1.1 varnish
etag: W/"15-5KajTCx0AJD0xogoSeOjjV2M8K0"
x-powered-by: Express
content-type: application/json; charset=utf-8
x-cloud-trace-context: 5a4bf6e8bc11cad911029b4927ac67c0
Accept-Ranges: bytes
Age: 0
Date: Mon, 12 Jan 2026 16:40:41 GMT
X-Served-By: cache-lax-kwhp1940080-LAX, cache-lax-kwhp1940093-LAX
X-Cache: MISS, MISS
X-Cache-Hits: 0, 0
X-Timer: S1768236042.568372,VS0,VE253
vcl-version: 6
x-platform: GCP
Vary: Accept-Encoding,Origin
{"error":"Not Found"}
Open service 199.232.194.133:443 · sltywh-ep.prisamedia.com
2026-01-12 16:40
HTTP/1.1 404 Not Found
Connection: close
Content-Length: 21
via: 1.1 google, 1.1 varnish, 1.1 varnish
etag: W/"15-5KajTCx0AJD0xogoSeOjjV2M8K0"
x-powered-by: Express
content-type: application/json; charset=utf-8
x-cloud-trace-context: 186f92e6851fbdd6e580b814e1e86025;o=1
Accept-Ranges: bytes
Date: Mon, 12 Jan 2026 16:40:35 GMT
Age: 2
X-Served-By: cache-pao-kpao1770040-PAO, cache-pao-kpao1770040-PAO
X-Cache: MISS, HIT
X-Cache-Hits: 0, 1
X-Timer: S1768236035.353511,VS0,VE0
vcl-version: 6
x-platform: GCP
Vary: Accept-Encoding,Origin
{"error":"Not Found"}
Open service 199.232.198.133:80 · sltywh-ep.prisamedia.com
2026-01-12 16:40
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Retry-After: 0 Location: https://sltywh-ep.prisamedia.com/ Accept-Ranges: bytes Date: Mon, 12 Jan 2026 16:40:35 GMT Via: 1.1 varnish X-Served-By: cache-yyz4523-YYZ X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1768236035.085770,VS0,VE1 vcl-version: 6 x-platform: GCP Vary: Origin
Open service 199.232.194.133:80 · sltywh-ep.prisamedia.com
2026-01-12 16:40
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Retry-After: 0 Location: https://sltywh-ep.prisamedia.com/ Accept-Ranges: bytes Date: Mon, 12 Jan 2026 16:40:35 GMT Via: 1.1 varnish X-Served-By: cache-lga21953-LGA X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1768236035.014552,VS0,VE1 vcl-version: 6 x-platform: GCP Vary: Origin
Open service 35.190.52.136:80 · backstage.prisamedia.com
2026-01-12 13:39
HTTP/1.1 502 Bad Gateway Content-Type: text/html; charset=UTF-8 Referrer-Policy: no-referrer Content-Length: 332 Date: Mon, 12 Jan 2026 13:40:31 GMT Connection: close Page title: 502 Server Error <html><head> <meta http-equiv="content-type" content="text/html;charset=utf-8"> <title>502 Server Error</title> </head> <body text=#000000 bgcolor=#ffffff> <h1>Error: Server Error</h1> <h2>The server encountered a temporary error and could not complete your request.<p>Please try again in 30 seconds.</h2> <h2></h2> </body></html>
Open service 146.75.118.133:80 · prisamedia.com
2026-01-12 08:58
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://prisamedia.com/ Accept-Ranges: bytes Date: Mon, 12 Jan 2026 08:58:14 GMT Via: 1.1 varnish X-Served-By: cache-fra-eddf8230190-FRA X-Cache: HIT X-Cache-Hits: 0 vcl-version: 41
Open service 146.75.118.133:443 · prisamedia.com
2026-01-12 08:58
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://prisa.com Accept-Ranges: bytes Date: Mon, 12 Jan 2026 08:58:13 GMT Via: 1.1 varnish X-Served-By: cache-fra-eddf8230020-FRA X-Cache: HIT X-Cache-Hits: 0 vcl-version: 41
Open service 136.110.217.158:443 · backstage-dev.prisamedia.com
2026-01-11 18:13
HTTP/1.1 200 OK
Server: nginx/1.29.2
Date: Sun, 11 Jan 2026 18:13:35 GMT
Content-Type: text/html
Content-Length: 3525
Last-Modified: Fri, 19 Dec 2025 12:20:07 GMT
Vary: Accept-Encoding
ETag: "694542f7-dc5"
Cache-Control: no-cache, no-store, must-revalidate
Pragma: no-cache
Expires: 0
Accept-Ranges: bytes
Via: 1.1 google
Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000
Connection: close
Page title: Backstage - Prisa Media
<!doctype html><html lang="en"><head><meta charset="utf-8"/><meta name="viewport" content="width=device-width,initial-scale=1"/><meta name="theme-color" content="#000000"/><meta name="description" content="Backstage is an open source framework for building developer portals"/><link rel="manifest" href="/manifest.json" crossorigin="use-credentials"/><link rel="icon" href="/favicon.ico"/><link rel="shortcut icon" href="/favicon.ico"/><link rel="apple-touch-icon" sizes="180x180" href="/apple-touch-icon.png"/><link rel="icon" type="image/png" sizes="32x32" href="/favicon-32x32.png"/><link rel="icon" type="image/png" sizes="16x16" href="/favicon-16x16.png"/><link rel="mask-icon" href="/safari-pinned-tab.svg" color="#5bbad5"/><title>Backstage - Prisa Media</title><meta name="backstage-app-mode" content="public"><script defer="defer" src="/static/runtime.2489892a.js"></script><script defer="defer" src="/static/module-backstage.1b4759f0.js"></script><script defer="defer" src="/static/module-material-ui.24b20cdf.js"></script><script defer="defer" src="/static/module-lodash.61c5e1a4.js"></script><script defer="defer" src="/static/module-date-fns.41ce547a.js"></script><script defer="defer" src="/static/module-azure.598a2c68.js"></script><script defer="defer" src="/static/module-yaml.256d0929.js"></script><script defer="defer" src="/static/module-typespec.d1bbafee.js"></script><script defer="defer" src="/static/module-mui.dd7c6cc0.js"></script><script defer="defer" src="/static/module-material-table.ab2705e1.js"></script><script defer="defer" src="/static/module-dagrejs.fe52d00e.js"></script><script defer="defer" src="/static/module-backstage-community.f0ea06e0.js"></script><script defer="defer" src="/static/module-micromark-core-commonmark.6d530f9d.js"></script><script defer="defer" src="/static/module-zod.1507b320.js"></script><script defer="defer" src="/static/module-react-dom.bca76fd2.js"></script><script defer="defer" src="/static/module-luxon.4bc9a4e3.js"></script><script defer="defer" src="/static/module-i18next.bb92c791.js"></script><script defer="defer" src="/static/module-react-beautiful-dnd.632617bb.js"></script><script defer="defer" src="/static/module-remix-run.a7c3d136.js"></script><script defer="defer" src="/static/vendor.1dc44157.js"></script><script defer="defer" src="/static/main.c6ddebcc.js"></script><link href="/static/vendor.c070e72d.css" rel="stylesheet"><script type="backstage.io/config">[
{
"context": "app-config.yaml",
"data": {
"app": {
"title": "Backstage - Prisa Media",
"baseUrl": "http://localhost:8080"
},
"auth": {
"environment": "production",
"providers": {
"oauth2Proxy": {}
}
},
"backend": {
"baseUrl": "http://localhost:7007"
},
"catalog": {
"import": {
"entityFilename": "catalog-info.yaml",
"pullRequestBranchName": "backstage-integration"
}
},
"integrations": {
"github": [
{
"host": "github.com"
}
]
},
"organization": {
"name": "Prisa Media"
}
}
},
{
"context": "app-config.production.yaml",
"data": {
"app": {
"baseUrl": "https://backstage-dev.prisamedia.com"
},
"backend": {
"baseUrl": "https://backstage-dev.prisamedia.com"
}
}
}
]</script></head><body><noscript>You need to enable JavaScript to run this app.</noscript><div id="root"></div></body></html>