nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 144.91.118.128:443 · git.rodara.es
2024-12-22 04:37
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Sun, 22 Dec 2024 04:37:12 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFPAFAXH1M8MG46FEFHS8QC9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFPAFAXH1M8MG46FEFHS8QC9 X-Runtime: 0.469601 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>
Open service 144.91.118.128:443 · git.rodara.es
2024-12-20 07:16
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Fri, 20 Dec 2024 07:16:43 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFHET01Y4GP2JK87VCXM1A49","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFHET01Y4GP2JK87VCXM1A49 X-Runtime: 0.188227 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>
Open service 144.91.118.128:443 · git.rodara.es
2024-12-18 22:03
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Wed, 18 Dec 2024 22:03:52 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFDWRZXWGH76320GFFMATX14","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFDWRZXWGH76320GFFMATX14 X-Runtime: 0.271684 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>
Open service 144.91.118.128:443 · git.rodara.es
2024-12-14 09:00
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Sat, 14 Dec 2024 09:00:05 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF26AYA3E723K2QKZFPB8V7T","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF26AYA3E723K2QKZFPB8V7T X-Runtime: 0.305623 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>
Open service 144.91.118.128:443 · git.rodara.es
2024-12-12 15:48
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Thu, 12 Dec 2024 15:48:25 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXRX70K9JPDZ3VY7SFZRZDV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXRX70K9JPDZ3VY7SFZRZDV X-Runtime: 0.199178 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>
Open service 144.91.118.128:443 · git.rodara.es
2024-12-03 02:04
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Tue, 03 Dec 2024 02:04:43 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE546FHXSSFR30GTNWJW5Z8C","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE546FHXSSFR30GTNWJW5Z8C X-Runtime: 0.177593 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>
Open service 144.91.118.128:443 · git.rodara.es
2024-12-01 00:52
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Sun, 01 Dec 2024 00:52:21 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZV8HWY3AAN461B74HYKEQT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZV8HWY3AAN461B74HYKEQT X-Runtime: 0.085129 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>
Open service 144.91.118.128:443 · git.rodara.es
2024-11-28 20:27
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Thu, 28 Nov 2024 20:27:47 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDT7ANKSC6E344QTW68HS2MP","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDT7ANKSC6E344QTW68HS2MP X-Runtime: 0.152337 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>
Open service 144.91.118.128:443 · git.rodara.es
2024-11-20 20:58
HTTP/1.1 302 Found Alt-Svc: h3=":443"; ma=2592000,h3-29=":443"; ma=2592000 Cache-Control: no-cache Content-Length: 100 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Wed, 20 Nov 2024 20:58:15 GMT Location: https://git.rodara.es/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=31536000; includeSubDomains; preload X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD5NWQ9YDBYYTGZCEBMJRFM8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD5NWQ9YDBYYTGZCEBMJRFM8 X-Runtime: 0.090251 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="http://git.rodara.es/users/sign_in">redirected</a>.</body></html>