nginx
tcp/443 tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 213.251.181.69:80 · gitlab.alea-prevention.ovh
2024-12-21 03:02
HTTP/1.1 301 Moved Permanently Server: nginx Date: Sat, 21 Dec 2024 03:02:10 GMT Content-Type: text/html Content-Length: 162 Connection: close Location: https://gitlab.alea-prevention.ovh:443/ X-Frame-Options: SAMEORIGIN X-Content-Type-Options: nosniff X-Xss-Protection: 1; mode=block Content-Security-Policy: default-src https: data: 'unsafe-inline' 'unsafe-eval' Strict-Transport-Security: max-age=31536000; includeSubdomains Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx</center> </body> </html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-12-21 03:02
HTTP/1.1 302 Found Server: nginx Date: Sat, 21 Dec 2024 03:02:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFKJMNWX3WW4VFJ77XXFC5R8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFKJMNWX3WW4VFJ77XXFC5R8 X-Runtime: 0.024198 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-12-20 15:58
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 15:58:18 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFJCN206QG1SKEMZ79ZNNC84","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFJCN206QG1SKEMZ79ZNNC84 X-Runtime: 0.012887 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-12-19 02:12
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 02:12:17 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFEAZV7MQJWQVH2YEKVYQXT2","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFEAZV7MQJWQVH2YEKVYQXT2 X-Runtime: 0.010149 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-12-14 15:51
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 15:51:26 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2XW5JV49EJGCAG9RKZ19B1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2XW5JV49EJGCAG9RKZ19B1 X-Runtime: 0.011071 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-12-13 02:05
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 02:05:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYW7JSTNEVKXR8JSEP5WDTR","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYW7JSTNEVKXR8JSEP5WDTR X-Runtime: 0.023175 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-12-02 19:11
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 19:11:29 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4CHVA931SNQA54HTZSS2XF","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4CHVA931SNQA54HTZSS2XF X-Runtime: 0.021458 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-11-30 14:44
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 14:44:05 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYRESHQFZD3M3PT8T1ERD8Y","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYRESHQFZD3M3PT8T1ERD8Y X-Runtime: 0.009044 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-11-28 19:03
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 19:03:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDT2GG0A0VMJ4XYGXTD5VMGZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDT2GG0A0VMJ4XYGXTD5VMGZ X-Runtime: 0.012044 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>
Open service 213.251.181.69:443 · gitlab.alea-prevention.ovh
2024-11-20 19:56
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 19:56:20 GMT Content-Type: text/html; charset=utf-8 Content-Length: 114 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.alea-prevention.ovh/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD5JBAZZ25HR032BDRDJK74C","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD5JBAZZ25HR032BDRDJK74C X-Runtime: 0.012785 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.alea-prevention.ovh/users/sign_in">redirected</a>.</body></html>