cloudflare
tcp/443
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d603073f8703073f8703073f8703073f8703073f87
GraphQL introspection enabled at /api/graphql Detected: GitLab
Severity: medium
Fingerprint: c2db3a1c40d490db2337d3d62337d3d62337d3d62337d3d62337d3d62337d3d6
GraphQL introspection enabled at /api/graphql
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 104.26.1.196:443 · gitlab.iappsbeats.com
2026-01-10 11:26
HTTP/1.1 302 Found
Date: Sat, 10 Jan 2026 11:26:55 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 109
Connection: close
Server: cloudflare
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.iappsbeats.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KEKTHJH9QDX70YBKH20Q61S0","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KEKTHJH9QDX70YBKH20Q61S0
X-Runtime: 0.026931
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
cf-cache-status: DYNAMIC
CF-RAY: 9bbbd27c89e745e1-FRA
alt-svc: h3=":443"; ma=86400
<html><body>You are being <a href="https://gitlab.iappsbeats.com/users/sign_in">redirected</a>.</body></html>
Open service 172.67.75.211:443 · gitlab.iappsbeats.com
2026-01-09 23:55
HTTP/1.1 302 Found
Date: Fri, 09 Jan 2026 23:55:19 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 109
Connection: close
Server: cloudflare
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.iappsbeats.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KEJJZ6KDJ8F280GXMFGTFV6C","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KEJJZ6KDJ8F280GXMFGTFV6C
X-Runtime: 0.063642
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
cf-cache-status: DYNAMIC
CF-RAY: 9bb7dd63b8b0a220-YYZ
alt-svc: h3=":443"; ma=86400
<html><body>You are being <a href="https://gitlab.iappsbeats.com/users/sign_in">redirected</a>.</body></html>
Open service 172.67.75.211:443 · gitlab.iappsbeats.com
2026-01-02 21:04
HTTP/1.1 302 Found
Date: Fri, 02 Jan 2026 21:04:23 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 109
Connection: close
Server: cloudflare
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.iappsbeats.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KE08D6A0CHMB2WWXXQKS8FP3","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KE08D6A0CHMB2WWXXQKS8FP3
X-Runtime: 0.046543
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
cf-cache-status: DYNAMIC
CF-RAY: 9b7d3561ce031d7b-YYZ
alt-svc: h3=":443"; ma=86400
<html><body>You are being <a href="https://gitlab.iappsbeats.com/users/sign_in">redirected</a>.</body></html>
Open service 172.67.75.211:443 · gitlab.iappsbeats.com
2025-12-23 05:54
HTTP/1.1 302 Found
Date: Tue, 23 Dec 2025 05:54:17 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 109
Connection: close
Server: cloudflare
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.iappsbeats.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KD4WBJJ3TP65CNA0EFM9K6V8","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KD4WBJJ3TP65CNA0EFM9K6V8
X-Runtime: 0.021806
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
cf-cache-status: DYNAMIC
CF-RAY: 9b259a7c3e249dfd-BLR
alt-svc: h3=":443"; ma=86400
<html><body>You are being <a href="https://gitlab.iappsbeats.com/users/sign_in">redirected</a>.</body></html>
Open service 172.67.75.211:443 · gitlab.iappsbeats.com
2025-12-23 02:15
HTTP/1.1 302 Found
Date: Tue, 23 Dec 2025 02:15:01 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 109
Connection: close
Server: cloudflare
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.iappsbeats.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KD4FT2RW6B7W8HP2HZJ4M5TJ","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KD4FT2RW6B7W8HP2HZJ4M5TJ
X-Runtime: 0.025411
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
cf-cache-status: DYNAMIC
CF-RAY: 9b24594ad87f7a09-LHR
alt-svc: h3=":443"; ma=86400
<html><body>You are being <a href="https://gitlab.iappsbeats.com/users/sign_in">redirected</a>.</body></html>
Open service 172.67.75.211:443 · gitlab.iappsbeats.com
2025-12-21 08:34
HTTP/1.1 302 Found
Date: Sun, 21 Dec 2025 08:34:34 GMT
Content-Type: text/html; charset=utf-8
Transfer-Encoding: chunked
Connection: close
Server: cloudflare
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.iappsbeats.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KD00QM4X9XWQJKXZCEPN5821","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KD00QM4X9XWQJKXZCEPN5821
X-Runtime: 0.043390
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
cf-cache-status: DYNAMIC
CF-RAY: 9b160a86ed919255-FRA
alt-svc: h3=":443"; ma=86400
<html><body>You are being <a href="https://gitlab.iappsbeats.com/users/sign_in">redirected</a>.</body></html>
Open service 172.67.75.211:443 · gitlab.iappsbeats.com
2025-12-19 05:26
HTTP/1.1 302 Found
Date: Fri, 19 Dec 2025 05:26:54 GMT
Content-Type: text/html; charset=utf-8
Content-Length: 109
Connection: close
Server: cloudflare
Cache-Control: no-cache
Content-Security-Policy:
Location: https://gitlab.iappsbeats.com/users/sign_in
Nel: {"max_age": 0}
Permissions-Policy: interest-cohort=()
Referrer-Policy: strict-origin-when-cross-origin
X-Content-Type-Options: nosniff
X-Download-Options: noopen
X-Frame-Options: SAMEORIGIN
X-Gitlab-Meta: {"correlation_id":"01KCTH6HQ08D9CCS69T44NJC8N","version":"1"}
X-Permitted-Cross-Domain-Policies: none
X-Request-Id: 01KCTH6HQ08D9CCS69T44NJC8N
X-Runtime: 0.115940
X-Ua-Compatible: IE=edge
X-Xss-Protection: 1; mode=block
cf-cache-status: DYNAMIC
CF-RAY: 9b047cdd9a56dbfe-FRA
alt-svc: h3=":443"; ma=86400
<html><body>You are being <a href="https://gitlab.iappsbeats.com/users/sign_in">redirected</a>.</body></html>