nginx
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 185.189.27.25:443 · git.dariel.kz
2026-01-10 00:47
HTTP/1.1 302 Found
Server: nginx
Date: Sat, 10 Jan 2026 00:47:14 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KEJNY8WKG0RHEGDK8KNVGD15","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KEJNY8WKG0RHEGDK8KNVGD15
X-Runtime: 0.028386
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2026-01-09 13:54
HTTP/1.1 302 Found
Server: nginx
Date: Fri, 09 Jan 2026 13:54:47 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KEHGKKJK8BSTA1CAJ39K6QSZ","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KEHGKKJK8BSTA1CAJ39K6QSZ
X-Runtime: 0.060858
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2026-01-02 19:16
HTTP/1.1 302 Found
Server: nginx
Date: Fri, 02 Jan 2026 19:16:31 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KE027P662VAWYCB7C48VVRFE","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KE027P662VAWYCB7C48VVRFE
X-Runtime: 0.071156
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2026-01-02 07:50
HTTP/1.1 302 Found
Server: nginx
Date: Fri, 02 Jan 2026 07:50:49 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KDYV045R8X2JZB2A35DXV23N","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KDYV045R8X2JZB2A35DXV23N
X-Runtime: 0.027878
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2025-12-23 08:58
HTTP/1.1 302 Found
Server: nginx
Date: Tue, 23 Dec 2025 08:58:42 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KD56X7ED3Q65R98V09QMD346","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KD56X7ED3Q65R98V09QMD346
X-Runtime: 0.069712
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2025-12-23 06:37
HTTP/1.1 302 Found
Server: nginx
Date: Tue, 23 Dec 2025 06:37:13 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KD4YT5SPC6N93D43PM2EWM7S","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KD4YT5SPC6N93D43PM2EWM7S
X-Runtime: 0.035217
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2025-12-21 06:13
HTTP/1.1 302 Found
Server: nginx
Date: Sun, 21 Dec 2025 06:13:19 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KCZRMZXZXYY5CZ9R2F4X72A0","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KCZRMZXZXYY5CZ9R2F4X72A0
X-Runtime: 0.028375
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2025-12-21 05:39
HTTP/1.1 302 Found
Server: nginx
Date: Sun, 21 Dec 2025 05:39:37 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KCZPQ98D0TAM7N20RTX9XAZG","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KCZPQ98D0TAM7N20RTX9XAZG
X-Runtime: 0.028933
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2025-12-19 07:44
HTTP/1.1 302 Found
Server: nginx
Date: Fri, 19 Dec 2025 07:44:31 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KCTS2HA25R4QVF6RP7PA69AA","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KCTS2HA25R4QVF6RP7PA69AA
X-Runtime: 0.042747
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>
Open service 185.189.27.25:443 · git.dariel.kz
2025-12-19 05:18
HTTP/1.1 302 Found
Server: nginx
Date: Fri, 19 Dec 2025 05:18:06 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 101
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://git.dariel.kz/users/sign_in
Permissions-Policy: interest-cohort=()
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KCTGPEJ8Y5CSER9QMJX1QGYE","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KCTGPEJ8Y5CSER9QMJX1QGYE
X-Runtime: 0.074624
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=63072000
Referrer-Policy: strict-origin-when-cross-origin
<html><body>You are being <a href="https://git.dariel.kz/users/sign_in">redirected</a>.</body></html>