cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3375fd2ff1e8f33cd93a8a577ab6b331343350003
GraphQL introspection enabled at /graphql Types: 24 (by kind: ENUM: 3, OBJECT: 12, SCALAR: 9) Operations: - Query: Query | fields: _empty - Subscription: Subscription | fields: directus_files_mutated Directives: deprecated, include, skip (total: 3)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d9181c39a346585bfbe2b3f59676f8159676f815
GraphQL introspection enabled at /graphql Types: 12 (by kind: ENUM: 2, OBJECT: 7, SCALAR: 3) Operations: - Query: Query | fields: _empty Directives: deprecated, include, skip (total: 3)
Open service 172.67.141.28:443 · scale.withdario.com
2026-01-08 22:48
HTTP/1.1 302 Found
Date: Thu, 08 Jan 2026 22:48:23 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 29
Connection: close
Server: cloudflare
location: ./admin
content-security-policy: script-src 'self' 'unsafe-eval' https://www.youtube.com https://player.vimeo.com;worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://cdn.directus.io https://images.unsplash.com https://avatars.githubusercontent.com https://gravatar.com https://secure.gravatar.com https://raw.githubusercontent.com https://i.ytimg.com https://superset.withdario.com https://images.pexels.com;media-src 'self' https://cdn.plyr.io;connect-src https://superset.withdario.com http://superset.withdario.com 'self' https://scale.withdario.com wss://*;font-src https://superset.withdario.com 'self' https://scale.withdario.com data:;frame-src 'self' https://scale.withdario.com https://withdario.ch https://www.withdario.ch https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com undefined https://metabase.withdario.com https://superset.withdario.com http://superset.withdario.com;default-src 'self';base-uri 'self';form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
x-powered-by: Directus
vary: Origin, Accept
access-control-allow-credentials: true
access-control-expose-headers: Content-Range
x-served-by: scale.withdario.com
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=14,cfOrigin;dur=519
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=ss%2FPeQV5iw9f8xafCNSrzbOArMSmQMr9eUZSJRonXQQKljr2dEYfQSxD%2BbDGeh0xueFYy0QkzNa81XEOZ5YRH197BIuwe%2FINtCreiFktbRIc5sA%3D"}]}
CF-RAY: 9baf3df74a0c229f-SJC
alt-svc: h3=":443"; ma=86400
Found. Redirecting to ./admin
Open service 172.67.141.28:443 · scale.withdario.com
2026-01-02 13:29
HTTP/1.1 502 Bad Gateway Date: Fri, 02 Jan 2026 13:29:47 GMT Content-Type: text/plain; charset=UTF-8 Content-Length: 15 Connection: close Cache-Control: private, max-age=0, no-store, no-cache, must-revalidate, post-check=0, pre-check=0 Expires: Thu, 01 Jan 1970 00:00:01 GMT Referrer-Policy: same-origin Server-Timing: cfEdge;dur=12,cfOrigin;dur=295 X-Frame-Options: SAMEORIGIN Server: cloudflare CF-RAY: 9b7a9b752bd10c82-EWR alt-svc: h3=":443"; ma=86400 error code: 502
Open service 172.67.141.28:443 · scale.withdario.com
2025-12-22 07:49
HTTP/1.1 302 Found
Date: Mon, 22 Dec 2025 07:49:49 GMT
Content-Type: text/plain; charset=utf-8
Content-Length: 29
Connection: close
Server: cloudflare
location: ./admin
content-security-policy: script-src 'self' 'unsafe-eval' https://www.youtube.com https://player.vimeo.com;worker-src 'self' blob:;child-src 'self' blob:;img-src 'self' data: blob: https://cdn.directus.io https://images.unsplash.com https://avatars.githubusercontent.com https://gravatar.com https://secure.gravatar.com https://raw.githubusercontent.com https://i.ytimg.com https://superset.withdario.com https://images.pexels.com;media-src 'self' https://cdn.plyr.io;connect-src https://superset.withdario.com http://superset.withdario.com 'self' https://scale.withdario.com wss://*;font-src https://superset.withdario.com 'self' https://scale.withdario.com data:;frame-src 'self' https://scale.withdario.com https://withdario.ch https://www.withdario.ch https://www.youtube.com https://www.youtube-nocookie.com https://player.vimeo.com undefined https://metabase.withdario.com https://superset.withdario.com http://superset.withdario.com;default-src 'self';base-uri 'self';form-action 'self';frame-ancestors 'self';object-src 'none';script-src-attr 'none';style-src 'self' https: 'unsafe-inline'
x-powered-by: Directus
vary: Origin, Accept
access-control-allow-credentials: true
access-control-expose-headers: Content-Range
x-served-by: scale.withdario.com
cf-cache-status: DYNAMIC
Nel: {"report_to":"cf-nel","success_fraction":0.0,"max_age":604800}
Server-Timing: cfCacheStatus;desc="DYNAMIC"
Server-Timing: cfEdge;dur=13,cfOrigin;dur=762
Report-To: {"group":"cf-nel","max_age":604800,"endpoints":[{"url":"https://a.nel.cloudflare.com/report/v4?s=q%2BHSKYYJv%2BySYi%2BC0%2BJKBkkXfMX1Ha3sH4z1ADevwPSAOQgoVVc6pLwuJB37WALLunO6DLSSqd7vw9hL2KpfObChYfgkDcKOnpCTvEqdr%2Bt5pN4%3D"}]}
CF-RAY: 9b1e0651cfbf4148-BOM
alt-svc: h3=":443"; ma=86400
Found. Redirecting to ./admin