nginx 1.18.0
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 195.135.213.205:443 · git.hl39.ru
2024-12-21 09:30
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 21 Dec 2024 09:30:56 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.hl39.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFM8WF7JWMRA2K8TYGBBW8MT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFM8WF7JWMRA2K8TYGBBW8MT X-Runtime: 0.044303 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.hl39.ru/users/sign_in">redirected</a>.</body></html>
Open service 195.135.213.205:443 · git.hl39.ru
2024-12-20 23:36
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 20 Dec 2024 23:36:43 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.hl39.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFK6WDQNS3DWVBH6S3BJXXYW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFK6WDQNS3DWVBH6S3BJXXYW X-Runtime: 0.101258 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.hl39.ru/users/sign_in">redirected</a>.</body></html>
Open service 195.135.213.205:443 · git.hl39.ru
2024-12-19 02:55
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 19 Dec 2024 02:56:01 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.hl39.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFEDFXFD407ZA34XCD07C472","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFEDFXFD407ZA34XCD07C472 X-Runtime: 0.122410 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.hl39.ru/users/sign_in">redirected</a>.</body></html>
Open service 195.135.213.205:443 · git.hl39.ru
2024-12-14 15:19
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 14 Dec 2024 15:19:26 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.hl39.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2W1JN0MT60WV4XE156ES6D","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2W1JN0MT60WV4XE156ES6D X-Runtime: 0.129577 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.hl39.ru/users/sign_in">redirected</a>.</body></html>
Open service 195.135.213.205:443 · git.hl39.ru
2024-12-12 23:30
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 12 Dec 2024 23:30:11 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.hl39.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYKAPZNDPH847PJ5G58SPJV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYKAPZNDPH847PJ5G58SPJV X-Runtime: 0.120045 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.hl39.ru/users/sign_in">redirected</a>.</body></html>
Open service 195.135.213.205:443 · git.hl39.ru
2024-12-02 17:52
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Mon, 02 Dec 2024 17:52:11 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.hl39.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE480MM130CZK7501Q02D82A","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE480MM130CZK7501Q02D82A X-Runtime: 0.120045 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.hl39.ru/users/sign_in">redirected</a>.</body></html>
Open service 195.135.213.205:443 · git.hl39.ru
2024-11-30 19:03
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 30 Nov 2024 19:03:26 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.hl39.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZ79NWJQMGY3678ZYKJAMDX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZ79NWJQMGY3678ZYKJAMDX X-Runtime: 0.051997 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.hl39.ru/users/sign_in">redirected</a>.</body></html>
Open service 195.135.213.205:443 · git.hl39.ru
2024-11-28 08:13
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 28 Nov 2024 08:13:49 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.hl39.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRXAQYC331NMSWHKHX74Q0B","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRXAQYC331NMSWHKHX74Q0B X-Runtime: 0.125837 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.hl39.ru/users/sign_in">redirected</a>.</body></html>