The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c04599850d300c86916dc380ec3d131c4367
[core] repositoryformatversion = 1 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.aexp.com/amex-eng/reactsamplepoc fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.aexp.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0JjS0ZWUzdtVXNCand0VVFGUzh2Qklra0pSYldSVTRZMmVHUw== [branch "eks-internet"] remote = origin merge = refs/heads/eks-internet
Open service 92.123.104.39:443 · sampleeksappfe-dev.americanexpress.com
2026-01-23 08:18
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Access-Control-Allow-Origin: *
Accept-Ranges: bytes
Last-Modified: Fri, 04 Jul 2025 07:14:37 GMT
ETag: W/"ae-197d4498348"
x-envoy-upstream-service-time: 1
X-Akamai-Transformed: 9 174 0 pmb=mRUM,2
Expires: Fri, 23 Jan 2026 08:18:43 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 23 Jan 2026 08:18:43 GMT
Content-Length: 4877
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=148
Server-Timing: origin; dur=34
Akamai-Request-BC: [a=23.41.167.144,b=235641297,c=g,n=DE_HE_FRANKFURT,o=20940],[c=c,n=US_CA_SANJOSE,o=20940],[a=244,c=o]
Akamai-GRN: 0.90a72917.1769156322.e0b99d1
Server-Timing: ak_p; desc="1769156322855_388605840_235641297_18156_2557_0_8_-";dur=1
Page title: React Sample App
<!doctype html><html lang="en"><head><title>React Sample App</title><script defer="defer" src="/dist/main.bundle.js"></script>
<script>(window.BOOMR_mq=window.BOOMR_mq||[]).push(["addVar",{"rua.upush":"false","rua.cpush":"false","rua.upre":"false","rua.cpre":"false","rua.uprl":"false","rua.cprl":"false","rua.cprf":"false","rua.trans":"","rua.cook":"false","rua.ims":"false","rua.ufprl":"false","rua.cfprl":"false","rua.isuxp":"false","rua.texp":"norulematch","rua.ceh":"false","rua.ueh":"false","rua.ieh.st":"0"}]);</script>
<script>!function(e){var n="https://s.go-mpulse.net/boomerang/";if("False"=="True")e.BOOMR_config=e.BOOMR_config||{},e.BOOMR_config.PageParams=e.BOOMR_config.PageParams||{},e.BOOMR_config.PageParams.pci=!0,n="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="ESFPG-HD936-Z2EK4-5RU8H-8KJAV",function(){function e(){if(!o){var e=document.createElement("script");e.id="boomr-scr-as",e.src=window.BOOMR.url,e.async=!0,i.parentNode.appendChild(e),o=!0}}function t(e){o=!0;var n,t,a,r,d=document,O=window;if(window.BOOMR.snippetMethod=e?"if":"i",t=function(e,n){var t=d.createElement("script");t.id=n||"boomr-if-as",t.src=window.BOOMR.url,BOOMR_lstart=(new Date).getTime(),e=e||d.body,e.appendChild(t)},!window.addEventListener&&window.attachEvent&&navigator.userAgent.match(/MSIE [67]\./))return window.BOOMR.snippetMethod="s",void t(i.parentNode,"boomr-async");a=document.createElement("IFRAME"),a.src="about:blank",a.title="",a.role="presentation",a.loading="eager",r=(a.frameElement||a).style,r.width=0,r.height=0,r.border=0,r.display="none",i.parentNode.appendChild(a);try{O=a.contentWindow,d=O.document.open()}catch(_){n=document.domain,a.src="javascript:var d=document.open();d.domain='"+n+"';void(0);",O=a.contentWindow,d=O.document.open()}if(n)d._boomrl=function(){this.domain=n,t()},d.write("<bo"+"dy onload='document._boomrl();'>");else if(O._boomrl=function(){t()},O.addEventListener)O.addEventListener("load",O._boomrl,!1);else if(O.attachEvent)O.attachEvent("onload",O._boomrl);d.close()}function a(e){window.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!window.BOOMR||!window.BOOMR.version&&!window.BOOMR.snippetExecuted){window.BOOMR=window.BOOMR||{},window.BOOMR.snippetStart=(new Date).getTime(),window.BOOMR.snippetExecuted=!0,window.BOOMR.snippetVersion=12,window.BOOMR.url=n+"ESFPG-HD936-Z2EK4-5RU8H-8KJAV";var i=document.currentScript||document.getElementsByTagName("script")[0],o=!1,r=document.createElement("link");if(r.relList&&"function"==typeof r.relList.supports&&r.relList.supports("preload")&&"as"in r)window.BOOMR.snippetMethod="p",r.href=window.BOOMR.url,r.rel="preload",r.as="script",r.addEventListener("load",e),r.addEventListener("error",function(){t(!0)}),setTimeout(function(){if(!o)t(!0)},3e3),BOOMR_lstart=(new Date).getTime(),i.parentNode.appendChild(r);else t(!1);if(window.addEventListener)window.addEventListener("load",a,!1);else if(window.attachEvent)window.attachEvent("onload",a)}}(),"".length>0)if(e&&"performance"in e&&e.performance&&"function"==typeof e.performance.setResourceTimingBufferSize)e.performance.setResourceTimingBufferSize();!function(){if(BOOMR=e.BOOMR||{},BOOMR.plugins=BOOMR.plugins||{},!BOOMR.plugins.AK){var n=""=="true"?1:0,t="",a="2etnbss4pnuco2ltf3ra-f-a1a2acc0e-clientnsv4-s.akamaihd.net",i="false"=="true"?2:1,o={"ak.v":"39","ak.cp":"1312698","ak.ai":parseInt("787993",10),"ak.ol":"0","ak.cr":0,"ak.ipv":4,"ak.proto":"http/1.1","ak.rid":"e0b99d1","ak.r":40609,"ak.a2":n,"ak.m":"x","ak.n":"essl","ak.bpcip":"209.38.208.0","ak.cport":46322,"ak.gh":"23.41.167.144","ak.quicv":"","ak.tlsv":"tls1.3","ak.0rtt":"","ak.0rtt.ed":"","ak.csrc":"-","ak.acc":"bbr","ak.t":"1769156322","ak.ak":"hOBiQwZUYzCg5VSAfCLimQ==Ouxa6HQh1CsZZMtcV0c3pDPEoDgxUjKl9hvv3DVxMApdbqsbWlLRhTS4kGFAJP98isabbfroakP2fTrivdNCfKWqIX3T46GbPE8J42ogXF2SkOiKFJLEOZJTTOT7tvIDj2rBiyk2UifYHjbyE0cBOudLUmKaUxqcP5kNgeqni97fnjLwapbLdoQieDr54r7yjdnHgFM9eMOP8ItxqLaZyHdMSt3ieQHIzQZWRbY/iIQYa0Ct9riUBj6f6wjDVaUwsD0AiBoWGe2IsVl91MWEcCYhlgT7wWBvlAOxM/hOHztMOJoyNOYrjzeXgYXqffkIvVS4jXOpGXDZbvuC5ImWdSeMz7
Open service 92.123.104.39:443 · sampleeksappfe-dev.americanexpress.com
2026-01-09 13:29
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Access-Control-Allow-Origin: *
Accept-Ranges: bytes
Last-Modified: Fri, 04 Jul 2025 07:14:37 GMT
ETag: W/"ae-197d4498348"
x-envoy-upstream-service-time: 4
X-Akamai-Transformed: 9 174 0 pmb=mRUM,2
Expires: Fri, 09 Jan 2026 13:29:14 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 09 Jan 2026 13:29:14 GMT
Content-Length: 4879
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=193
Server-Timing: origin; dur=37
Akamai-Request-BC: [a=23.41.167.167,b=709787333,c=g,n=DE_HE_FRANKFURT,o=20940],[c=c,n=US_CA_SANJOSE,o=20940],[a=242,c=o]
Akamai-GRN: 0.a7a72917.1767965354.2a4e7ec5
Server-Timing: ak_p; desc="1767965354403_388605863_709787333_23008_5015_0_66_-";dur=1
Page title: React Sample App
<!doctype html><html lang="en"><head><title>React Sample App</title><script defer="defer" src="/dist/main.bundle.js"></script>
<script>(window.BOOMR_mq=window.BOOMR_mq||[]).push(["addVar",{"rua.upush":"false","rua.cpush":"false","rua.upre":"false","rua.cpre":"false","rua.uprl":"false","rua.cprl":"false","rua.cprf":"false","rua.trans":"","rua.cook":"false","rua.ims":"false","rua.ufprl":"false","rua.cfprl":"false","rua.isuxp":"false","rua.texp":"norulematch","rua.ceh":"false","rua.ueh":"false","rua.ieh.st":"0"}]);</script>
<script>!function(e){var n="https://s.go-mpulse.net/boomerang/";if("False"=="True")e.BOOMR_config=e.BOOMR_config||{},e.BOOMR_config.PageParams=e.BOOMR_config.PageParams||{},e.BOOMR_config.PageParams.pci=!0,n="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="ESFPG-HD936-Z2EK4-5RU8H-8KJAV",function(){function e(){if(!o){var e=document.createElement("script");e.id="boomr-scr-as",e.src=window.BOOMR.url,e.async=!0,i.parentNode.appendChild(e),o=!0}}function t(e){o=!0;var n,t,a,r,d=document,O=window;if(window.BOOMR.snippetMethod=e?"if":"i",t=function(e,n){var t=d.createElement("script");t.id=n||"boomr-if-as",t.src=window.BOOMR.url,BOOMR_lstart=(new Date).getTime(),e=e||d.body,e.appendChild(t)},!window.addEventListener&&window.attachEvent&&navigator.userAgent.match(/MSIE [67]\./))return window.BOOMR.snippetMethod="s",void t(i.parentNode,"boomr-async");a=document.createElement("IFRAME"),a.src="about:blank",a.title="",a.role="presentation",a.loading="eager",r=(a.frameElement||a).style,r.width=0,r.height=0,r.border=0,r.display="none",i.parentNode.appendChild(a);try{O=a.contentWindow,d=O.document.open()}catch(_){n=document.domain,a.src="javascript:var d=document.open();d.domain='"+n+"';void(0);",O=a.contentWindow,d=O.document.open()}if(n)d._boomrl=function(){this.domain=n,t()},d.write("<bo"+"dy onload='document._boomrl();'>");else if(O._boomrl=function(){t()},O.addEventListener)O.addEventListener("load",O._boomrl,!1);else if(O.attachEvent)O.attachEvent("onload",O._boomrl);d.close()}function a(e){window.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!window.BOOMR||!window.BOOMR.version&&!window.BOOMR.snippetExecuted){window.BOOMR=window.BOOMR||{},window.BOOMR.snippetStart=(new Date).getTime(),window.BOOMR.snippetExecuted=!0,window.BOOMR.snippetVersion=12,window.BOOMR.url=n+"ESFPG-HD936-Z2EK4-5RU8H-8KJAV";var i=document.currentScript||document.getElementsByTagName("script")[0],o=!1,r=document.createElement("link");if(r.relList&&"function"==typeof r.relList.supports&&r.relList.supports("preload")&&"as"in r)window.BOOMR.snippetMethod="p",r.href=window.BOOMR.url,r.rel="preload",r.as="script",r.addEventListener("load",e),r.addEventListener("error",function(){t(!0)}),setTimeout(function(){if(!o)t(!0)},3e3),BOOMR_lstart=(new Date).getTime(),i.parentNode.appendChild(r);else t(!1);if(window.addEventListener)window.addEventListener("load",a,!1);else if(window.attachEvent)window.attachEvent("onload",a)}}(),"".length>0)if(e&&"performance"in e&&e.performance&&"function"==typeof e.performance.setResourceTimingBufferSize)e.performance.setResourceTimingBufferSize();!function(){if(BOOMR=e.BOOMR||{},BOOMR.plugins=BOOMR.plugins||{},!BOOMR.plugins.AK){var n=""=="true"?1:0,t="",a="z6nmk4k4pnuco2lbakva-f-d3c28b66a-clientnsv4-s.akamaihd.net",i="false"=="true"?2:1,o={"ak.v":"39","ak.cp":"1312698","ak.ai":parseInt("787993",10),"ak.ol":"0","ak.cr":0,"ak.ipv":4,"ak.proto":"http/1.1","ak.rid":"2a4e7ec5","ak.r":40609,"ak.a2":n,"ak.m":"x","ak.n":"essl","ak.bpcip":"207.154.197.0","ak.cport":44588,"ak.gh":"23.41.167.167","ak.quicv":"","ak.tlsv":"tls1.3","ak.0rtt":"","ak.0rtt.ed":"","ak.csrc":"-","ak.acc":"bbr","ak.t":"1767965354","ak.ak":"hOBiQwZUYzCg5VSAfCLimQ==9MeNJ9/AXIi6XJTkDCXMAbmPr2IaWrrdJG1lmGVxzuSn0SiIERoXnLAw80MtUCg/Yfo/PVH60FcqAvYX4+duKeSws7YhggPMdXt1UMa3g34h5X0Ym49GJfYLPeocNBSwApoNO2V8kJrW+XEyFhvVuBuVfv2TT8tawnWsktpcdELLDgnotD3nvwhnk3bPbwJSvu+MNzeESumgPcNLjPMg9bvwnB9EXpGK3GrQWVrBFYHG2WxSE/UZ1QchsMm+ykWQZ0EAHrLjHzwwMTg6nfhGYe3q+xDJqzHbz0NpBnK4qH6wZj88018SvObrPsQU8DCZAeosVAaZ/vFVUBDcOxSc6YPb
Open service 92.123.104.39:443 · sampleeksappfe-dev.americanexpress.com
2026-01-02 19:38
HTTP/1.1 404 Not Found Content-Length: 0 Expires: Fri, 02 Jan 2026 19:38:50 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 19:38:50 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=809 Server-Timing: origin; dur=227 Akamai-Request-BC: [a=23.41.167.144,b=1112475874,c=g,n=DE_HE_FRANKFURT,o=20940],[c=c,n=US_CA_SANJOSE,o=20940],[a=242,c=o] Akamai-GRN: 0.90a72917.1767382729.424f08e2 Server-Timing: ak_p; desc="1767382729040_388605840_1112475874_103560_3142_83_162_-";dur=1
Open service 92.123.104.39:443 · sampleeksappfe-dev.americanexpress.com
2025-12-23 07:07
HTTP/1.1 200 OK
Content-Type: text/html; charset=UTF-8
Access-Control-Allow-Origin: *
Accept-Ranges: bytes
Last-Modified: Fri, 04 Jul 2025 07:14:37 GMT
ETag: W/"ae-197d4498348"
x-envoy-upstream-service-time: 1
X-Akamai-Transformed: 9 174 0 pmb=mRUM,2
Expires: Tue, 23 Dec 2025 07:07:11 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Tue, 23 Dec 2025 07:07:11 GMT
Content-Length: 4880
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=151
Server-Timing: origin; dur=97
Akamai-Request-BC: [a=23.41.167.144,b=392286196,c=g,n=DE_HE_FRANKFURT,o=20940],[c=c,n=US_CA_SANJOSE,o=20940],[a=242,c=o]
Akamai-GRN: 0.90a72917.1766473631.1761cff4
Server-Timing: ak_p; desc="1766473631325_388605840_392286196_24781_1772_91_92_-";dur=1
Page title: React Sample App
<!doctype html><html lang="en"><head><title>React Sample App</title><script defer="defer" src="/dist/main.bundle.js"></script>
<script>(window.BOOMR_mq=window.BOOMR_mq||[]).push(["addVar",{"rua.upush":"false","rua.cpush":"false","rua.upre":"false","rua.cpre":"false","rua.uprl":"false","rua.cprl":"false","rua.cprf":"false","rua.trans":"","rua.cook":"false","rua.ims":"false","rua.ufprl":"false","rua.cfprl":"false","rua.isuxp":"false","rua.texp":"norulematch","rua.ceh":"false","rua.ueh":"false","rua.ieh.st":"0"}]);</script>
<script>!function(e){var n="https://s.go-mpulse.net/boomerang/";if("False"=="True")e.BOOMR_config=e.BOOMR_config||{},e.BOOMR_config.PageParams=e.BOOMR_config.PageParams||{},e.BOOMR_config.PageParams.pci=!0,n="https://s2.go-mpulse.net/boomerang/";if(window.BOOMR_API_key="ESFPG-HD936-Z2EK4-5RU8H-8KJAV",function(){function e(){if(!o){var e=document.createElement("script");e.id="boomr-scr-as",e.src=window.BOOMR.url,e.async=!0,i.parentNode.appendChild(e),o=!0}}function t(e){o=!0;var n,t,a,r,d=document,O=window;if(window.BOOMR.snippetMethod=e?"if":"i",t=function(e,n){var t=d.createElement("script");t.id=n||"boomr-if-as",t.src=window.BOOMR.url,BOOMR_lstart=(new Date).getTime(),e=e||d.body,e.appendChild(t)},!window.addEventListener&&window.attachEvent&&navigator.userAgent.match(/MSIE [67]\./))return window.BOOMR.snippetMethod="s",void t(i.parentNode,"boomr-async");a=document.createElement("IFRAME"),a.src="about:blank",a.title="",a.role="presentation",a.loading="eager",r=(a.frameElement||a).style,r.width=0,r.height=0,r.border=0,r.display="none",i.parentNode.appendChild(a);try{O=a.contentWindow,d=O.document.open()}catch(_){n=document.domain,a.src="javascript:var d=document.open();d.domain='"+n+"';void(0);",O=a.contentWindow,d=O.document.open()}if(n)d._boomrl=function(){this.domain=n,t()},d.write("<bo"+"dy onload='document._boomrl();'>");else if(O._boomrl=function(){t()},O.addEventListener)O.addEventListener("load",O._boomrl,!1);else if(O.attachEvent)O.attachEvent("onload",O._boomrl);d.close()}function a(e){window.BOOMR_onload=e&&e.timeStamp||(new Date).getTime()}if(!window.BOOMR||!window.BOOMR.version&&!window.BOOMR.snippetExecuted){window.BOOMR=window.BOOMR||{},window.BOOMR.snippetStart=(new Date).getTime(),window.BOOMR.snippetExecuted=!0,window.BOOMR.snippetVersion=12,window.BOOMR.url=n+"ESFPG-HD936-Z2EK4-5RU8H-8KJAV";var i=document.currentScript||document.getElementsByTagName("script")[0],o=!1,r=document.createElement("link");if(r.relList&&"function"==typeof r.relList.supports&&r.relList.supports("preload")&&"as"in r)window.BOOMR.snippetMethod="p",r.href=window.BOOMR.url,r.rel="preload",r.as="script",r.addEventListener("load",e),r.addEventListener("error",function(){t(!0)}),setTimeout(function(){if(!o)t(!0)},3e3),BOOMR_lstart=(new Date).getTime(),i.parentNode.appendChild(r);else t(!1);if(window.addEventListener)window.addEventListener("load",a,!1);else if(window.attachEvent)window.attachEvent("onload",a)}}(),"".length>0)if(e&&"performance"in e&&e.performance&&"function"==typeof e.performance.setResourceTimingBufferSize)e.performance.setResourceTimingBufferSize();!function(){if(BOOMR=e.BOOMR||{},BOOMR.plugins=BOOMR.plugins||{},!BOOMR.plugins.AK){var n=""=="true"?1:0,t="",a="z266sjc4pnuco2kkh6pq-f-54a774d1d-clientnsv4-s.akamaihd.net",i="false"=="true"?2:1,o={"ak.v":"39","ak.cp":"1312698","ak.ai":parseInt("787993",10),"ak.ol":"0","ak.cr":89,"ak.ipv":4,"ak.proto":"http/1.1","ak.rid":"1761cff4","ak.r":40609,"ak.a2":n,"ak.m":"x","ak.n":"essl","ak.bpcip":"206.189.233.0","ak.cport":41058,"ak.gh":"23.41.167.144","ak.quicv":"","ak.tlsv":"tls1.3","ak.0rtt":"","ak.0rtt.ed":"","ak.csrc":"-","ak.acc":"bbr","ak.t":"1766473631","ak.ak":"hOBiQwZUYzCg5VSAfCLimQ==8RKBD1VLyPrwFj6AqRdq3m7gbKpe/UxM2m4WPPNI2O8+096HYy1aMy1TccjpsPRe2EN6KBFV1KxT7ARLWiJctaJ7NuNZ16z9QdhHLlW8rvPvFaowztZy2DX0s/UtjAdDbfhiY6NSXjBtUUv9g2Wd9pIY+CJNF1KnpXWYIa35BBV6G3SAUBdBgpwg2yUDlsfeBhMxSrm2/iPReTpxwBoNP2vtKGnPIMjI8nrkRSQYLGHpRWRn9IiOuWKhvz3yK31jd8tyGAtaC08YKnzVtcggHeufl1mPrC5evevRFxWweQLmwDjVT7YZYlQT0BPwE95eaTCjuJHpN7r/6QWgGDi39Cp