GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
Open service 35.168.89.203:443 · gitlab.aumbit.io
2026-01-09 17:05
HTTP/1.1 302 Found
Date: Fri, 09 Jan 2026 17:05:05 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.aumbit.io/users/sign_in
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KEHVG1RBX5FWEP67GN3K3Q13","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KEHVG1RBX5FWEP67GN3K3Q13
X-Runtime: 0.026702
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubDomains
<html><body>You are being <a href="https://gitlab.aumbit.io/users/sign_in">redirected</a>.</body></html>
Open service 35.168.89.203:443 · gitlab.aumbit.io
2026-01-02 17:46
HTTP/1.1 302 Found
Date: Fri, 02 Jan 2026 17:46:13 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.aumbit.io/users/sign_in
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KDZX2AQVJEGK05NNMV21SVJH","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KDZX2AQVJEGK05NNMV21SVJH
X-Runtime: 0.035248
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubDomains
<html><body>You are being <a href="https://gitlab.aumbit.io/users/sign_in">redirected</a>.</body></html>
Open service 35.168.89.203:443 · gitlab.aumbit.io
2025-12-23 08:18
HTTP/1.1 302 Found
Date: Tue, 23 Dec 2025 08:18:20 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.aumbit.io/users/sign_in
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KD54KAA3Y7DF8KXWV2T23BEF","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KD54KAA3Y7DF8KXWV2T23BEF
X-Runtime: 0.023837
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubDomains
<html><body>You are being <a href="https://gitlab.aumbit.io/users/sign_in">redirected</a>.</body></html>
Open service 35.168.89.203:443 · gitlab.aumbit.io
2025-12-21 07:03
HTTP/1.1 302 Found
Date: Sun, 21 Dec 2025 07:03:08 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.aumbit.io/users/sign_in
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KCZVG6F0C0PQKM6NA4JDWXBN","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KCZVG6F0C0PQKM6NA4JDWXBN
X-Runtime: 0.037228
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubDomains
<html><body>You are being <a href="https://gitlab.aumbit.io/users/sign_in">redirected</a>.</body></html>
Open service 35.168.89.203:443 · gitlab.aumbit.io
2025-12-19 01:17
HTTP/1.1 302 Found
Date: Fri, 19 Dec 2025 01:17:53 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.aumbit.io/users/sign_in
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KCT2YJKDJ3AVNTA6KMYJ5XH9","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KCT2YJKDJ3AVNTA6KMYJ5XH9
X-Runtime: 0.036770
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
Strict-Transport-Security: max-age=31536000; includeSubDomains
<html><body>You are being <a href="https://gitlab.aumbit.io/users/sign_in">redirected</a>.</body></html>