nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-12-21 02:02
HTTP/1.1 302 Found Server: nginx Date: Sat, 21 Dec 2024 02:02:33 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFKF7FCPTGKD2N8DWBN7CWCB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFKF7FCPTGKD2N8DWBN7CWCB X-Runtime: 0.017930 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-12-19 03:31
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 03:31:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFEFHCB6XMFANCTH0KTZM3FH","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFEFHCB6XMFANCTH0KTZM3FH X-Runtime: 0.038040 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-12-14 10:31
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 10:31:50 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2BJZ8DZ6S5YCNSZX4PQRHD","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2BJZ8DZ6S5YCNSZX4PQRHD X-Runtime: 0.034249 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-12-12 22:12
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 22:12:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYEWVYRNZGRTV06S8MY0N8E","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYEWVYRNZGRTV06S8MY0N8E X-Runtime: 0.037553 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-12-03 00:37
HTTP/1.1 302 Found Server: nginx Date: Tue, 03 Dec 2024 00:37:20 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4Z6G5NR3DNMA88QTS12021","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4Z6G5NR3DNMA88QTS12021 X-Runtime: 0.035112 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-11-30 17:12
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 17:13:02 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZ0ZGGTS6AG2Z1NZX212EVP","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZ0ZGGTS6AG2Z1NZX212EVP X-Runtime: 0.018354 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-11-28 16:00
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 16:00:51 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSR1X2GPCXWEFMHQ37PEFJP","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSR1X2GPCXWEFMHQ37PEFJP X-Runtime: 0.015399 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-11-26 22:39
HTTP/1.1 302 Found Server: nginx Date: Tue, 26 Nov 2024 22:39:54 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDNA353PXJVBWZ6MFHX0GY46","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDNA353PXJVBWZ6MFHX0GY46 X-Runtime: 0.016101 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>
Open service 74.235.192.159:443 · gitlab-sandbox-inovacao.eastus.cloudapp.azure.com
2024-11-21 00:46
HTTP/1.1 302 Found Server: nginx Date: Thu, 21 Nov 2024 00:46:14 GMT Content-Type: text/html; charset=utf-8 Content-Length: 137 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD62Y5RDFMVK318F67R4GJNR","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD62Y5RDFMVK318F67R4GJNR X-Runtime: 0.034388 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-sandbox-inovacao.eastus.cloudapp.azure.com/users/sign_in">redirected</a>.</body></html>