nginx 1.20.1
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 39.100.37.196:443 · git.yituanzi.com
2024-12-22 03:47
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Sun, 22 Dec 2024 03:47:50 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP7MYYJ8MTQXPMDCXEEF62R","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP7MYYJ8MTQXPMDCXEEF62R X-Runtime: 0.021196 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-12-20 06:25
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Fri, 20 Dec 2024 06:25:28 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFHBW52NV8JGJ52Y4DFPTXC6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFHBW52NV8JGJ52Y4DFPTXC6 X-Runtime: 0.017685 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-12-18 23:55
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Wed, 18 Dec 2024 23:55:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE35W1KWV54DFKX9PGPM34T","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE35W1KWV54DFKX9PGPM34T X-Runtime: 0.018459 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-12-14 14:43
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Sat, 14 Dec 2024 14:43:57 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2T0JX59YMTNQG7PTPGC0TM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2T0JX59YMTNQG7PTPGC0TM X-Runtime: 0.039043 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-12-12 12:17
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Thu, 12 Dec 2024 12:17:28 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXCTY6BA8269JVMCDC0YRXG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXCTY6BA8269JVMCDC0YRXG X-Runtime: 0.017945 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-12-02 10:05
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Mon, 02 Dec 2024 10:05:22 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE3D9VZ2RHDTRY7ESXV4HX6P","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE3D9VZ2RHDTRY7ESXV4HX6P X-Runtime: 0.018603 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-11-30 07:05
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Sat, 30 Nov 2024 07:05:57 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDXY7XKD9X6JR9DPDZNXFVZ0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDXY7XKD9X6JR9DPDZNXFVZ0 X-Runtime: 0.041857 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-11-29 00:11
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Fri, 29 Nov 2024 00:11:21 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDTM41YDXQH129ZFWRBE4RM6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDTM41YDXQH129ZFWRBE4RM6 X-Runtime: 0.021795 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-11-26 21:44
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Tue, 26 Nov 2024 21:44:31 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDN6XQYY4GPXTR697B1TVFYB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDN6XQYY4GPXTR697B1TVFYB X-Runtime: 0.040646 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>
Open service 39.100.37.196:443 · git.yituanzi.com
2024-11-21 01:16
HTTP/1.1 302 Found Server: nginx/1.20.1 Date: Thu, 21 Nov 2024 01:16:23 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://git.yituanzi.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD64NCA0NQM9XGSY7R5RS57X","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD64NCA0NQM9XGSY7R5RS57X X-Runtime: 0.018308 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.yituanzi.com/users/sign_in">redirected</a>.</body></html>