Heroku
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3fff1b62df954f68f8c0f2781472ed938a0628998
GraphQL introspection enabled at /graphql Types: 424 (by kind: ENUM: 44, INPUT_OBJECT: 178, INTERFACE: 1, OBJECT: 195, SCALAR: 6) Operations: - Query: Query | fields: checkSlug, companies, company, crcPurposes, creditBundles - Mutation: Mutation | fields: addAccountMember, addTfaPhoneNumber, archiveCheckLists, archiveDocuments, archivePeople Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
.DS_Store” is an abbreviation for “Desktop Services Store”. These files are created automatically by Apples “Finder” software (which is part of their OS).
They store information about the files within a folder, including display options of folders, such as icon positions and view settings.
It may happen that .DS_Store files inadvertently leak filenames such as database backups or private administration panels.
Severity: low
Fingerprint: 5f32cf5d6962f09c47dfe71947dfe719511acc516ca19a49c4e4557e8a466010
Found 16 files trough .DS_Store spidering: /404.html /422.html /500.html /agreement_individual.pdf /agreement_organization.pdf /apple-touch-icon.png /assets /favicon-16x16.png /favicon-32x32.png /favicon.ico /pop_agreement_individual.pdf /pop_agreement_organization.pdf /robots.txt /site.webmanifest /Varslingsrutiner.pdf /Varslingsrutiner.png
Open service 76.223.11.49:443 · qa.core.manymore.com
2026-01-08 23:15
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=yGZ37FotOxdKURMJ3LbifJ34R%2BDs1YiERnTwMNcjBmU%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767914138"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=yGZ37FotOxdKURMJ3LbifJ34R%2BDs1YiERnTwMNcjBmU%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767914138"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 25d6ca98-909f-c6dc-d2a5-22bcbdda1e5b
X-Runtime: 0.003275
X-Xss-Protection: 0
Date: Thu, 08 Jan 2026 23:15:38 GMT
Connection: close
Open service 54.247.69.169:443 · qa.core.manymore.com
2026-01-08 21:13
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=K0Dp83NxMKoWNaGj3obft1xizr4EMTSZQv%2B2%2FnAuPVs%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767906789"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=K0Dp83NxMKoWNaGj3obft1xizr4EMTSZQv%2B2%2FnAuPVs%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767906789"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: c48b5ebc-3a7b-4f1a-fb26-74ad1e45635c
X-Runtime: 0.002850
X-Xss-Protection: 0
Date: Thu, 08 Jan 2026 21:13:09 GMT
Connection: close
Open service 76.223.11.49:443 · qa.core.manymore.com
2026-01-01 22:41
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Arv61toMu3TATAPh720R2c5ZXgT4gQtUShLE5QIdR6A%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767307265"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Arv61toMu3TATAPh720R2c5ZXgT4gQtUShLE5QIdR6A%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767307265"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: ffe50dbe-1200-5503-df13-3114c1979350
X-Runtime: 0.003326
X-Xss-Protection: 0
Date: Thu, 01 Jan 2026 22:41:05 GMT
Connection: close
Open service 76.223.11.49:443 · qa.core.manymore.com
2025-12-30 07:45
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=B8rEULZkcJmXkG7V6n9IAOaQOJvbIw%2FyI%2FFK4PPhQpU%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767080713"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=B8rEULZkcJmXkG7V6n9IAOaQOJvbIw%2FyI%2FFK4PPhQpU%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767080713"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 023321b4-89c0-ab86-b164-b4b601316885
X-Runtime: 0.012016
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 07:45:13 GMT
Connection: close
Open service 54.247.69.169:443 · qa.core.manymore.com
2025-12-30 05:01
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=T4Bos6XyWFQ4dKJibqo2pBFY7a7sknp8GEnEP7VXtaE%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1767070889"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=T4Bos6XyWFQ4dKJibqo2pBFY7a7sknp8GEnEP7VXtaE%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1767070889"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 8cbc7346-a1c7-8391-4684-9205ec79c9c2
X-Runtime: 0.004315
X-Xss-Protection: 0
Date: Tue, 30 Dec 2025 05:01:29 GMT
Connection: close
Open service 76.223.11.49:443 · qa.core.manymore.com
2025-12-22 06:20
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=CPqAzJqdd2IvFSuMhZ0HTIZuCuYGXd2C4oEu32zPyC4%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766384458"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=CPqAzJqdd2IvFSuMhZ0HTIZuCuYGXd2C4oEu32zPyC4%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766384458"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: d924b800-63f7-3694-245b-41982053d89c
X-Runtime: 0.002745
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 06:20:58 GMT
Connection: close
Open service 54.247.69.169:443 · qa.core.manymore.com
2025-12-22 05:59
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Tpkq569CU1cvZaqhAr3qVtkRR%2BheOv7%2FCGEhQmvxGNw%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766383196"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Tpkq569CU1cvZaqhAr3qVtkRR%2BheOv7%2FCGEhQmvxGNw%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766383196"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 9a14786c-af6e-caca-722c-6a52b768cf7c
X-Runtime: 0.002717
X-Xss-Protection: 0
Date: Mon, 22 Dec 2025 05:59:56 GMT
Connection: close
Open service 76.223.11.49:443 · qa.core.manymore.com
2025-12-20 19:56
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=DegFg9jpQ4BLSTkJyqroLQwaSN%2FGG4NUMkaCbdF5VQI%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766260617"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=DegFg9jpQ4BLSTkJyqroLQwaSN%2FGG4NUMkaCbdF5VQI%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766260617"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 10c49227-e0f9-5f88-4d96-db63d847966a
X-Runtime: 0.006821
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 19:56:57 GMT
Connection: close
Open service 54.247.69.169:443 · qa.core.manymore.com
2025-12-20 06:31
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=KFcd36iBWBzy5XbCgDUfrGfinDJZy4F3KVIjociqSA0%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766212289"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=KFcd36iBWBzy5XbCgDUfrGfinDJZy4F3KVIjociqSA0%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766212289"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 18ef51c0-8a7a-0aad-4240-ee1e4329fd42
X-Runtime: 0.004992
X-Xss-Protection: 0
Date: Sat, 20 Dec 2025 06:31:29 GMT
Connection: close
Open service 76.223.11.49:443 · qa.core.manymore.com
2025-12-19 01:20
HTTP/1.1 302 Found
Cache-Control: no-store
Content-Length: 0
Content-Type: text/html; charset=utf-8
Location: https://qa.core.manymore.com/admin/session/new
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Referrer-Policy: strict-origin-when-cross-origin
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=eOv4blq2gZVU2LUC4YQJxtJvBU0FfcE%2Firh1t%2FWHdic%3D\u0026sid=c4c9725f-1ab0-44d8-820f-430df2718e11\u0026ts=1766107217"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=eOv4blq2gZVU2LUC4YQJxtJvBU0FfcE%2Firh1t%2FWHdic%3D&sid=c4c9725f-1ab0-44d8-820f-430df2718e11&ts=1766107217"
Server: Heroku
Strict-Transport-Security: max-age=63072000; includeSubDomains
Via: 1.1 heroku-router
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 20c92228-b4e9-c617-79fd-1bed292a2bb3
X-Runtime: 0.006057
X-Xss-Protection: 0
Date: Fri, 19 Dec 2025 01:20:17 GMT
Connection: close