nginx
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 46.126.81.198:443 ยท code.statesystems.ch
2026-01-23 09:58
HTTP/1.1 302 Found
Cache-Control: no-cache
Content-Length: 108
Content-Security-Policy:
Content-Type: text/html; charset=utf-8
Date: Fri, 23 Jan 2026 09:59:21 GMT
Location: https://code.statesystems.ch/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
Server: nginx
Strict-Transport-Security: max-age=63072000
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KFN4PJGASXXQYHK4XTRG8S44","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KFN4PJGASXXQYHK4XTRG8S44
X-Runtime: 0.062379
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Connection: close
<html><body>You are being <a href="https://code.statesystems.ch/users/sign_in">redirected</a>.</body></html>