GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa34478cff04aae00f48f3ef4f13a49742096ac4272
GraphQL introspection enabled at /graphql Types: 217 (by kind: ENUM: 29, INPUT_OBJECT: 27, INTERFACE: 4, OBJECT: 153, SCALAR: 4) Operations: - Query: Query | fields: tenantProfile, tenantPropertyLeaseDetailsByApplicationId, tenantPropertyLeaseDetailsByInvitationId, tenantPropertyLeaseDetailsByListingId, tenantPropertyLeaseDetailsByListingIdAndRegistrationId - Mutation: Mutation | fields: createDocument, createQuestionnaireDocument, deleteDocument, deleteDocuments, deleteQuestionnaireDocument Directives: deprecated, include, skip, specifiedBy (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3b7f21ff6974ebbe62ede4147ae14869e8063e988
GraphQL introspection enabled at /graphql Types: 216 (by kind: ENUM: 28, INPUT_OBJECT: 27, INTERFACE: 4, OBJECT: 153, SCALAR: 4) Operations: - Query: Query | fields: tenantProfile, tenantPropertyLeaseDetailsByApplicationId, tenantPropertyLeaseDetailsByInvitationId, tenantPropertyLeaseDetailsByListingId, tenantPropertyLeaseDetailsByListingIdAndRegistrationId - Mutation: Mutation | fields: createDocument, createQuestionnaireDocument, deleteDocument, deleteDocuments, deleteQuestionnaireDocument Directives: deprecated, include, skip, specifiedBy (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31671a6aaad1ac99a2ba962fbdf497e2a5b6a2a9c
GraphQL introspection enabled at /graphql Types: 201 (by kind: ENUM: 27, INPUT_OBJECT: 27, INTERFACE: 3, OBJECT: 140, SCALAR: 4) Operations: - Query: Query | fields: tenantProfile, tenantPropertyLeaseDetailsByApplicationId, tenantPropertyLeaseDetailsByInvitationId, tenantPropertyLeaseDetailsByListingId, tenantPropertyLeaseDetailsByListingIdAndRegistrationId - Mutation: Mutation | fields: createDocument, createQuestionnaireDocument, deleteDocument, deleteDocuments, deleteQuestionnaireDocument Directives: deprecated, include, skip, specifiedBy (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ce32349792eb5245920819d425e747bd774641e9
GraphQL introspection enabled at /graphql Types: 199 (by kind: ENUM: 27, INPUT_OBJECT: 27, INTERFACE: 3, OBJECT: 138, SCALAR: 4) Operations: - Query: Query | fields: tenantProfile, tenantPropertyLeaseDetailsByApplicationId, tenantPropertyLeaseDetailsByInvitationId, tenantPropertyLeaseDetailsByListingId, tenantPropertyLeaseDetailsByListingIdAndRegistrationId - Mutation: Mutation | fields: createDocument, createQuestionnaireDocument, deleteDocument, deleteDocuments, deleteQuestionnaireDocument Directives: deprecated, include, skip, specifiedBy (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3bac534feae9bc02e669924b9293373e66aa0da42
GraphQL introspection enabled at /graphql Types: 148 (by kind: ENUM: 11, INPUT_OBJECT: 17, INTERFACE: 1, OBJECT: 105, SCALAR: 9, UNION: 5) Operations: - Query: Query | fields: WwsReEngagementCarousel, bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa356801e86dfc71b76d339c4916e73682e8a0f655a
GraphQL introspection enabled at /graphql Types: 146 (by kind: ENUM: 10, INPUT_OBJECT: 17, INTERFACE: 1, OBJECT: 104, SCALAR: 9, UNION: 5) Operations: - Query: Query | fields: WwsReEngagementCarousel, bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3574f1f47805e8c7587f5c538c74843a329c94ecb
GraphQL introspection enabled at /graphql Types: 145 (by kind: ENUM: 9, INPUT_OBJECT: 17, INTERFACE: 1, OBJECT: 104, SCALAR: 9, UNION: 5) Operations: - Query: Query | fields: WwsReEngagementCarousel, bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3a4f010dfe1d182ede53c3e807477065b275faaf3
GraphQL introspection enabled at /graphql Types: 142 (by kind: ENUM: 9, INPUT_OBJECT: 17, INTERFACE: 1, OBJECT: 102, SCALAR: 9, UNION: 4) Operations: - Query: Query | fields: WwsReEngagementCarousel, bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa338327a333d86c43197117064ded970ffc15196a7
GraphQL introspection enabled at /graphql Types: 140 (by kind: ENUM: 9, INPUT_OBJECT: 17, INTERFACE: 1, OBJECT: 100, SCALAR: 9, UNION: 4) Operations: - Query: Query | fields: WwsReEngagementCarousel, bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3a1c48fe237c6a2b29bed96f41efa1c4f0e3b3a37
GraphQL introspection enabled at /graphql Types: 138 (by kind: ENUM: 9, INPUT_OBJECT: 17, INTERFACE: 1, OBJECT: 98, SCALAR: 9, UNION: 4) Operations: - Query: Query | fields: bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary, budgeter - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3450e1818ac0e90fce3df8f866708085de4f78179
GraphQL introspection enabled at /graphql Types: 137 (by kind: ENUM: 8, INPUT_OBJECT: 17, INTERFACE: 1, OBJECT: 98, SCALAR: 9, UNION: 4) Operations: - Query: Query | fields: bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary, budgeter - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3fffc33ce3ec1473e00b1f2481e5751f37f1b61db
GraphQL introspection enabled at /graphql Types: 136 (by kind: ENUM: 8, INPUT_OBJECT: 17, INTERFACE: 1, OBJECT: 97, SCALAR: 9, UNION: 4) Operations: - Query: Query | fields: bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary, budgeter - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3432b58d46ce8cf1813609a4a0cccce1172dfc02d
GraphQL introspection enabled at /graphql Types: 134 (by kind: ENUM: 8, INPUT_OBJECT: 16, INTERFACE: 1, OBJECT: 96, SCALAR: 9, UNION: 4) Operations: - Query: Query | fields: bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary, budgeter - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3c33b169ccdeebea003550c02b4f271d970c43f45
GraphQL introspection enabled at /graphql Types: 133 (by kind: ENUM: 8, INPUT_OBJECT: 16, INTERFACE: 1, OBJECT: 95, SCALAR: 9, UNION: 4) Operations: - Query: Query | fields: bookingStatsSummary, bookings, budgetAdviceDetail, budgetStatsSummary, budgeter - Mutation: Mutation | fields: addBulkVendorBookings, addVendorBooking, nullifyPhaseGoalSequence, updateBulkGoalVisibility, updateGoalVisibility Directives: deprecated, include, oneOf, skip, specifiedBy (total: 5)
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522c53c5bbe
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzIxa1Z5UlF2UkNzWmxWQnZ1dm1mVkVwZk5pRHZzZjJyV3llcA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522fcd06152
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3BVMmlEeWNIclZYVENpV2RjcDVPN2JGcWlxREJZRTJoTmxoTQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65226aa7eb02
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX05qUEJUbjYzNjE0V0ZlRXNFS0J2Q1ZMWDVtV1VJejB3NXdrag==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65227e1d9621
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0FqZVIzR1B3QURKWHh6SlVxRjBVbGNDamQ4cXYwMDNySWdmNA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a07190f6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1l6TjVKN3MyZWFhRm9XN1V4ZXlJaGI4dUpUTWVZWjJ0VFF1Uw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522bc6688d9
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzBEekVxZWlDeURGVDFXTW9Ra2NmYmZsZDQ2Njc2STROUDFtVQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a909a8ab
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2l2dngxc05VTWtZVUo3UU40Mjk5TElKQ1o3MWJoQjRWb1Bxeg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65221dd9bdfd
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0piT2RKck1mVnR1NlExWDNVZm9hQWY4S25jcUZNbzBEOFNVMw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65224e99a70c
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3JDYjVRQ2lncVRFQ2hsUlJ4cHFFMG9ENjZUZkV0VDBLbGVkRg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f3b682a7
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0ZFTHhvb1ZHQlE0OUZtV0hTUDIwQ05PNUVLRmU5MjFVU1dFVA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65223be77afd
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1lldmxicXA5YmpDSW9qclZMQjl3QjJXSnZab0xGeDI4aVdrRw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522ba9f70cf
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2xkWnVKSFgwTG8wTVRWbTkzRE5ROE9xUk9EeWFFODQ0Z2Y0cA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228358accb
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0RLdXNvY0h2S1JsWDRkS1Boc1dGa3c2bTBjcTFUSTN4b1BQSw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522142593a6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2NjY01Ca1lYMTRQc29FSTZLRnJPM2pyZ3oyQ1VkOTM0cTRiUg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652248c93102
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzAybGN0UkY5NUh3bU9RQ3Baak5FMFJRQmVXQWJ0WTBqMHU5UQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652268ff39d2
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1JmcEFXcEhURTV5RnBYODlOZFhIRlRkb0trVGtTTzM2S2RSQg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522217e2f41
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3dSRVljOHhEYklRY2daZFBGUnM4dHU5amFQQmJyejNMd0Z1Mg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228b2af2d8
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1RPZ3A1NlN6YzJJN2JXRVBlYVdJaUJFd3JiS1lOTTNnc25tSQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522027a27af
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzVMUUVrV3ppejk4TlVRN0dHQ1RtUzY5MzVTaGdsOTE4VVE3ZA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522520095a0
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2ZKM09HbGdpMGl2dWd2cEQwQTdzaHdnYjB5NFJISDBPaHpxZw==
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e34ac788
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2FmbnBnR0JUa2JWejlqOFBxb09VSzRJdmVwM1VldjBXUXUxUg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652241a5374b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2VaT0wyQTA2Wk1CR1E5aEU0N2VqaFA3MGNMZnY4NjJkekg0Ng==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652282d719d3
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2I5eVdRcHl0MENMQTdwR3ZjTTNyWVBNNkNGNVBoWTFSTWY2NQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652270631dec
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzdpUGx4UUZCV1IzUHp5aWpib0g5alA0ZTlmd2h5czNOd3RZMQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522978f100d
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2dBdkQ2YUJNR0IwUU8zUmZIRG5SNmFySnhHcVZIeDNwZzZUMw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e1747cb4
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3Q4VEdIRVhZenJBd2cyUEMxNG5jRVRHSk11YUVQeTFIM0VKMQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522931b2f0f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2VQQXNXaUtUUnRFcHFFWUhvdWg5V21NVjduYmo2UjM3OWttSg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522c66552b3
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0Q2OXl1U3lXdGlKem5GVGpYOWFnaUs0ajExS0w4aDJ0WWlscg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522590c0e20
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0NUdjF6djk1bVdiSFN4aVhEd1k5MXVOVXliNUR4TzBXTmV3dg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652236849c5b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2YwdE1iUXBLVlJPYmNvQU5aNW82ejdDd3JxbEl0MDJCU2ttZQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228b2908d5
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0NtS2dCRFgySWlUOWE3WWl2QnhSdkJjOGZMeU9VRzNabklZYg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65221605088e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0NCbWZ5Y2pjU2NIeXJHRmFibU80V2V0NnlIMzNRRDM2MUtsdw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d9348e8b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzZIaXFMdnU5Vm5ZOFFXakFiZmtJYWtEcE5Bd082SzNxNVNKUw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652252451c9c
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1cxRlhYMHVnYUdXVFptclJRU1NMaUtud0tzd1hKdDJleUpXOQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522ff5ce839
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1A1UzVyYThIbGVtY1M1U0paQmowWk5pdnF1eUtQQzJYb29udA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652297b5a835
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1pTWlBrVWNCT3V1c1VYZlAwNFprbnVzMDFXb1dPOTBneHlmYQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652241774cf4
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0FYOWpuc3NmSmZEaERhQXRNTEIxYnlSNTV6U3d4NDNPaGFvUQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522134100f8
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2FUcjNNYXcwaGtCVUVOS0dZOWJUNExIQ0hQeDR2UDNUa2NUMw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652203042ea9
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3d5ZEd0cDBua2FudXVPS205YjZJVXd0dUVOM1IyYjBhUmM3VA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652229e35896
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0NsM3lqZmhTenYyZEczZzBob1BDUldST0o1V2FIcTNvVlJDTA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65224e804b3d
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0ZybTlzRnpaWVdBWXlnbENEMmN2NWR5ZkR0bE9XaDJPR1pqUw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f65f1ce8
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0JkM1NmRkdUZW9NTUNBamtEOHlNV1ZTNUJodTF1dDBCRVJ4RQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f342b8cf
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX01tRXJsMlFBNFE5MHJscVFMTlU0MHBCcHNwcHhQbDJuZ0xucw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522b035fe86
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0lGekh6cjA4VjU0TTZkSW1CRXlBWG9MR1hSbXJYbTJjQXdmbQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f01076b6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3E2UFhTY1M2OHg0blFZZ2lOaktJRWFsVHVJcks4dDNsQjJ0NQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65221b4a834c
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzNFNXFkalNhUmVXWGJXaEl5TmkydDdoQUlLRkhkNTFxUHdXZA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652257dd6964
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2lYQnoySmRURXM3MElERXVjRTZJZlc4d05WN0NjazFmaU1XZA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a7bbd8a0
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzJlT09aVlE5a0swT0wwWGJjaENvaUcyWDJVdmdHQjQ4cUtOTg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522887252c7
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3lNOGxoeGxaQzczeEJwZW9JTTk2ODF0bUpXbHJxazNoTDQzYw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a99f112f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0JTN3VkTHRQUGxYZVBWdFdVUk1KbFlSV1J5Uk1KSTNhdGx4Mg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f8a09204
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2lGcHpxN2JOWlh4MmhmWjZHRllscmpERWt1Nm5CUjJTeXJIbQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522b0865608
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3gwNmVrTmRncTQ1dVpxYUVrZHhrSnBRWW1WOHZPQTNTQ0pEQg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228fa59e6f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX21kUnl0eG10T3dTN0pvR0VLMnNxUGlhTlN4ZlJENTQ5dnc2cA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65220646709d
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX21EaW9DN0h4QTh1U0NmcHMzem9STGRxSjdFT0hFYzJ5YmlvNw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522164136bd
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2JmcnFXS0c2RERPSnpNWTFjaW5QYUVSOFpBZ1dmTTBRdU9xdg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65221658efc8
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzl4UlRndTFpZXdhS012NmxiT0NIWjJUclZYV2p1YjN1Y2RHRA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652219c810d6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1ZBTVMyaVlqNzBwTWhFREtHS2dmeU1wM2lXbHg3MDMzMEw4TQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652280176a8a
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1U5VmhlSzFVRzN5OFJBQXV4ZFVZeDU3bGFvd3lJMzNmVWRxdw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652274bfc2c3
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3FtZkZma1dHN0E5TEJucHlFTmo2VWVPdU4xSU5lOTRDVVltMQ==
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa31a0bbaa3
GraphQL introspection enabled at /graphql
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d95651f3b4672a71d38cf3fa5522653c7f141d05
GraphQL introspection enabled at /graphql Types: 951 (by kind: ENUM: 4, INPUT_OBJECT: 183, OBJECT: 753, SCALAR: 10, UNION: 1) Operations: - Query: Query | fields: pdd_products, pdd_products_aggregated, pdd_products_by_id, pdd_products_by_version, pdd_products_translations - Mutation: Mutation | fields: pdd_create_products_from_to_attributes_items, pdd_create_products_item, pdd_create_products_items, pdd_create_products_translations_item, pdd_create_products_translations_items - Subscription: Subscription | fields: pdd_colors_mutated, pdd_products_from_to_attributes_mutated, pdd_products_mutated, pdd_products_surfaces_mutated, pdd_products_translations_mutated Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3d95651f3b4672a71d38cf3fa5522653c0e46f51d
GraphQL introspection enabled at /graphql Types: 951 (by kind: ENUM: 4, INPUT_OBJECT: 183, OBJECT: 753, SCALAR: 10, UNION: 1) Operations: - Query: Query | fields: pdd_products, pdd_products_aggregated, pdd_products_by_id, pdd_products_by_version, pdd_products_translations - Mutation: Mutation | fields: pdd_create_products_from_to_attributes_items, pdd_create_products_item, pdd_create_products_items, pdd_create_products_translations_item, pdd_create_products_translations_items - Subscription: Subscription | fields: pdd_colors_mutated, pdd_products_from_to_attributes_mutated, pdd_products_mutated, pdd_products_surfaces_mutated, pdd_products_translations_mutated Directives: deprecated, include, skip, specifiedBy (total: 4)
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d607a5b498b1d6f03e9a6323bd1337c611c337c611c
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths: GET /auth/login GET /auth/logout GET /auth/signup GET /auth/userinfo
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa33337941030119dd4c4df5d62a2295c631d6d31ab
GraphQL introspection enabled at /graphql Types: 665 (by kind: ENUM: 45, INPUT_OBJECT: 131, INTERFACE: 28, OBJECT: 456, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e21d2abba504fdf2a71079c281ed0e4056b66e01e0
GraphQL introspection enabled at /graphql/api Types: 665 (by kind: ENUM: 45, INPUT_OBJECT: 131, INTERFACE: 28, OBJECT: 456, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3fc0cc541384de24317d5ddbd1d572a5ae45a0824
GraphQL introspection enabled at /graphql Types: 684 (by kind: ENUM: 45, INPUT_OBJECT: 141, INTERFACE: 28, OBJECT: 464, SCALAR: 5, UNION: 1) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e260cd4c6f17cfc73db5fec10b73a330ec2bb8d9ee
GraphQL introspection enabled at /graphql/api Types: 670 (by kind: ENUM: 45, INPUT_OBJECT: 132, INTERFACE: 28, OBJECT: 460, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3b3e2a42ee001ecde4eb65258c42f420dd772f5a5
GraphQL introspection enabled at /graphql Types: 670 (by kind: ENUM: 45, INPUT_OBJECT: 132, INTERFACE: 28, OBJECT: 460, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e21d2abba504fdf2a71079c281ed0e4056b66e01e0
GraphQL introspection enabled at /graphql/api Types: 665 (by kind: ENUM: 45, INPUT_OBJECT: 131, INTERFACE: 28, OBJECT: 456, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa35d5488b2d3aa5d429871225c50afecf9dc357c21
GraphQL introspection enabled at /graphql Types: 672 (by kind: ENUM: 45, INPUT_OBJECT: 132, INTERFACE: 28, OBJECT: 462, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa36d6b0c2826eaa80c0a3d30aa62c671bb4a2fa523
GraphQL introspection enabled at /graphql Types: 668 (by kind: ENUM: 45, INPUT_OBJECT: 132, INTERFACE: 28, OBJECT: 458, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e260cd4c6f17cfc73db5fec10b73a330ec2bb8d9ee
GraphQL introspection enabled at /graphql/api Types: 670 (by kind: ENUM: 45, INPUT_OBJECT: 132, INTERFACE: 28, OBJECT: 460, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ee6245a1a9900b6321490ddd8c15fd7ab95fe644
GraphQL introspection enabled at /graphql Types: 685 (by kind: ENUM: 45, INPUT_OBJECT: 141, INTERFACE: 28, OBJECT: 465, SCALAR: 5, UNION: 1) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e2f3034f94d545fd5881408466b2164fcff8c0a4f7
GraphQL introspection enabled at /graphql/api Types: 685 (by kind: ENUM: 45, INPUT_OBJECT: 141, INTERFACE: 28, OBJECT: 465, SCALAR: 5, UNION: 1) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3c60b308182da0303d0c2607ddf31591a5c7331e4
GraphQL introspection enabled at /graphql Types: 686 (by kind: ENUM: 45, INPUT_OBJECT: 141, INTERFACE: 28, OBJECT: 466, SCALAR: 5, UNION: 1) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
stage-station.api.npr.org 39 stage4-station.api.npr.org 20 qa.plan-api.planningtools.theknot.com 10 tenant-experience-api.realestate.com.au 4 preprod.omegawatches.com 4 backend.sormat.com 3 release.omegawatches.com 3 preview.omegawatches.com 3 webmaster.omegawatches.com 2 gamnextstg.mcd.com 1 api.admin.cookiebot.com 1