Varnish
tcp/80
nginx
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3a20f87454ad3ea87b77edd276c51b75bc533e15f
GraphQL introspection enabled at /graphql Types: 13 (by kind: ENUM: 2, OBJECT: 8, SCALAR: 3) Operations: - Query: Query | fields: currentUser Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Open service 151.101.65.91:443 · support-dev.allizom.org
2026-01-10 02:03
HTTP/1.1 302 Found Connection: close Content-Length: 0 via: 1.1 google, 1.1 varnish, 1.1 varnish x-backend-server: gha-sumo-web-689695c8b4-f9bpb.nonprod.webservices.mozgcp.net referrer-policy: strict-origin-when-cross-origin server: nginx cross-origin-opener-policy: same-origin accept-ranges: bytes location: /en-US/ strict-transport-security: max-age=31536000 content-type: text/html; charset=utf-8 x-content-type-options: nosniff Date: Sat, 10 Jan 2026 02:03:25 GMT X-Served-By: cache-vie6326-VIE, cache-vie6326-VIE X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1768010605.257852,VS0,VE260 Vary: Accept-Language, Cookie
Open service 151.101.65.91:443 · support-dev.allizom.org
2026-01-02 23:58
HTTP/1.1 302 Found Connection: close Content-Length: 0 content-type: text/html; charset=utf-8 cross-origin-opener-policy: same-origin server: nginx x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-kjb2v.nonprod.webservices.mozgcp.net strict-transport-security: max-age=31536000 location: /en-US/ Date: Fri, 02 Jan 2026 23:58:23 GMT X-Served-By: cache-lcy-egml8630036-LCY, cache-lcy-egml8630088-LCY X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1767398303.397983,VS0,VE208 Vary: Accept-Language, Cookie
Open service 151.101.65.91:443 · support-dev.allizom.org
2025-12-23 09:54
HTTP/1.1 302 Found Connection: close Content-Length: 0 content-type: text/html; charset=utf-8 cross-origin-opener-policy: same-origin server: nginx x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-kjb2v.nonprod.webservices.mozgcp.net strict-transport-security: max-age=31536000 location: /en-US/ Date: Tue, 23 Dec 2025 09:54:03 GMT X-Served-By: cache-lga21943-LGA, cache-lga21970-LGA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766483643.151285,VS0,VE135 Vary: Accept-Language, Cookie
Open service 151.101.65.91:443 · support-dev.allizom.org
2025-12-21 09:57
HTTP/1.1 302 Found Connection: close Content-Length: 0 content-type: text/html; charset=utf-8 cross-origin-opener-policy: same-origin server: nginx x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-kjb2v.nonprod.webservices.mozgcp.net strict-transport-security: max-age=31536000 location: /en-US/ Date: Sun, 21 Dec 2025 09:57:13 GMT X-Served-By: cache-sin-wsss1830069-SIN, cache-sin-wsss1830093-SIN X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766311033.143948,VS0,VE743 Vary: Accept-Language, Cookie
Open service 151.101.193.91:80 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 301 Moved permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://support-dev.allizom.org/ Accept-Ranges: bytes Date: Fri, 19 Dec 2025 16:22:02 GMT Via: 1.1 varnish X-Served-By: cache-sin-wsat1880020-SIN X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1766161323.759921,VS0,VE0
Open service 151.101.1.91:80 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 301 Moved permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://support-dev.allizom.org/ Accept-Ranges: bytes Date: Fri, 19 Dec 2025 16:22:02 GMT Via: 1.1 varnish X-Served-By: cache-sin-wsat1880074-SIN X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1766161323.755068,VS0,VE0
Open service 151.101.65.91:443 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 302 Found Connection: close Content-Length: 0 content-type: text/html; charset=utf-8 cross-origin-opener-policy: same-origin server: nginx x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-kjb2v.nonprod.webservices.mozgcp.net strict-transport-security: max-age=31536000 location: /en-US/ Date: Fri, 19 Dec 2025 16:22:03 GMT X-Served-By: cache-yyz4554-YYZ, cache-yyz4554-YYZ X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766161323.042000,VS0,VE386 Vary: Accept-Language, Cookie
Open service 151.101.129.91:443 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 302 Found Connection: close Content-Length: 0 content-type: text/html; charset=utf-8 cross-origin-opener-policy: same-origin server: nginx x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-kjb2v.nonprod.webservices.mozgcp.net strict-transport-security: max-age=31536000 location: /en-US/ Date: Fri, 19 Dec 2025 16:22:03 GMT X-Served-By: cache-fra-eddf8230143-FRA, cache-fra-eddf8230143-FRA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766161323.043613,VS0,VE665 Vary: Accept-Language, Cookie
Open service 2a04:4e42:200::347:443 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 302 Found Connection: close Content-Length: 0 accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-w9vm2.nonprod.webservices.mozgcp.net server: nginx referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish content-type: text/html; charset=utf-8 location: /en-US/ strict-transport-security: max-age=31536000 x-content-type-options: nosniff cross-origin-opener-policy: same-origin Date: Fri, 19 Dec 2025 16:22:03 GMT X-Served-By: cache-lcy-egml8630056-LCY, cache-lcy-egml8630045-LCY X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766161323.332296,VS0,VE637 Vary: Accept-Language, Cookie
Open service 151.101.65.91:80 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 301 Moved permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://support-dev.allizom.org/ Accept-Ranges: bytes Date: Fri, 19 Dec 2025 16:22:02 GMT Via: 1.1 varnish X-Served-By: cache-vie6380-VIE X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1766161323.747828,VS0,VE1
Open service 2a04:4e42::347:443 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 302 Found Connection: close Content-Length: 0 accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-kjb2v.nonprod.webservices.mozgcp.net server: nginx referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish content-type: text/html; charset=utf-8 location: /en-US/ strict-transport-security: max-age=31536000 x-content-type-options: nosniff cross-origin-opener-policy: same-origin Date: Fri, 19 Dec 2025 16:22:03 GMT X-Served-By: cache-fra-eddf8230099-FRA, cache-fra-eddf8230099-FRA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766161323.933096,VS0,VE264 Vary: Accept-Language, Cookie
Open service 2a04:4e42:200::347:80 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 301 Moved permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://support-dev.allizom.org/ Accept-Ranges: bytes Date: Fri, 19 Dec 2025 16:22:02 GMT Via: 1.1 varnish X-Served-By: cache-lga21955-LGA X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1766161323.648512,VS0,VE1
Open service 151.101.1.91:443 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 302 Found Connection: close Content-Length: 0 content-type: text/html; charset=utf-8 cross-origin-opener-policy: same-origin server: nginx x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-kjb2v.nonprod.webservices.mozgcp.net strict-transport-security: max-age=31536000 location: /en-US/ Date: Fri, 19 Dec 2025 16:22:03 GMT X-Served-By: cache-bom-vanm7210053-BOM, cache-bom-vanm7210053-BOM X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766161323.116891,VS0,VE352 Vary: Accept-Language, Cookie
Open service 2a04:4e42:400::347:80 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 301 Moved permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://support-dev.allizom.org/ Accept-Ranges: bytes Date: Fri, 19 Dec 2025 16:22:02 GMT Via: 1.1 varnish X-Served-By: cache-fra-eddf8230112-FRA X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1766161323.608657,VS0,VE0
Open service 151.101.129.91:80 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 301 Moved permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://support-dev.allizom.org/ Accept-Ranges: bytes Date: Fri, 19 Dec 2025 16:22:02 GMT Via: 1.1 varnish X-Served-By: cache-fra-eddf8230075-FRA X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1766161323.609979,VS0,VE0
Open service 2a04:4e42:600::347:443 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 302 Found Connection: close Content-Length: 0 accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-w9vm2.nonprod.webservices.mozgcp.net server: nginx referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish content-type: text/html; charset=utf-8 location: /en-US/ strict-transport-security: max-age=31536000 x-content-type-options: nosniff cross-origin-opener-policy: same-origin Date: Fri, 19 Dec 2025 16:22:03 GMT X-Served-By: cache-pao-kpao1770056-PAO, cache-pao-kpao1770037-PAO X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766161323.333081,VS0,VE115 Vary: Accept-Language, Cookie
Open service 2a04:4e42:400::347:443 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 302 Found Connection: close Content-Length: 0 accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-w9vm2.nonprod.webservices.mozgcp.net server: nginx referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish content-type: text/html; charset=utf-8 location: /en-US/ strict-transport-security: max-age=31536000 x-content-type-options: nosniff cross-origin-opener-policy: same-origin Date: Fri, 19 Dec 2025 16:22:03 GMT X-Served-By: cache-lga21987-LGA, cache-lga21967-LGA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766161323.924082,VS0,VE151 Vary: Accept-Language, Cookie
Open service 2a04:4e42::347:80 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 301 Moved permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://support-dev.allizom.org/ Accept-Ranges: bytes Date: Fri, 19 Dec 2025 16:22:02 GMT Via: 1.1 varnish X-Served-By: cache-yyz4576-YYZ X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1766161323.810514,VS0,VE1
Open service 2a04:4e42:600::347:80 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 301 Moved permanently Connection: close Content-Length: 0 Server: Varnish Retry-After: 0 Location: https://support-dev.allizom.org/ Accept-Ranges: bytes Date: Fri, 19 Dec 2025 16:22:02 GMT Via: 1.1 varnish X-Served-By: cache-fra-eddf8230137-FRA X-Cache: HIT X-Cache-Hits: 0 X-Timer: S1766161323.569417,VS0,VE0
Open service 151.101.193.91:443 · support-dev.allizom.org
2025-12-19 16:22
HTTP/1.1 302 Found Connection: close Content-Length: 0 content-type: text/html; charset=utf-8 cross-origin-opener-policy: same-origin server: nginx x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-w9vm2.nonprod.webservices.mozgcp.net strict-transport-security: max-age=31536000 location: /en-US/ Date: Fri, 19 Dec 2025 16:22:03 GMT X-Served-By: cache-fra-eddf8230059-FRA, cache-fra-eddf8230059-FRA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766161323.843707,VS0,VE736 Vary: Accept-Language, Cookie
Open service 151.101.65.91:443 · support-dev.allizom.org
2025-12-19 02:29
HTTP/1.1 302 Found Connection: close Content-Length: 0 content-type: text/html; charset=utf-8 cross-origin-opener-policy: same-origin server: nginx x-content-type-options: nosniff referrer-policy: strict-origin-when-cross-origin via: 1.1 google, 1.1 varnish, 1.1 varnish accept-ranges: bytes x-backend-server: gha-sumo-web-689695c8b4-w9vm2.nonprod.webservices.mozgcp.net strict-transport-security: max-age=31536000 location: /en-US/ Date: Fri, 19 Dec 2025 02:29:03 GMT X-Served-By: cache-yyz4534-YYZ, cache-yyz4548-YYZ X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766111343.421894,VS0,VE569 Vary: Accept-Language, Cookie