nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-12-22 04:41
HTTP/1.1 302 Found server: nginx date: Sun, 22 Dec 2024 04:41:02 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JFPAPCP14Y6HF6QYZT7JTM1E","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JFPAPCP14Y6HF6QYZT7JTM1E x-runtime: 0.062981 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-12-20 05:07
HTTP/1.1 302 Found server: nginx date: Fri, 20 Dec 2024 05:07:14 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JFH7CXAD9JX5MCHGYZ7MEM8K","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JFH7CXAD9JX5MCHGYZ7MEM8K x-runtime: 0.040258 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-12-19 03:13
HTTP/1.1 302 Found server: nginx date: Thu, 19 Dec 2024 03:13:52 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JFEEGKG2WQSBD3RHVZHMSFPD","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JFEEGKG2WQSBD3RHVZHMSFPD x-runtime: 0.042469 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-12-14 15:33
HTTP/1.1 302 Found server: nginx date: Sat, 14 Dec 2024 15:33:04 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JF2WTHCMW2A4Y2NEK4EF36WZ","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JF2WTHCMW2A4Y2NEK4EF36WZ x-runtime: 0.038618 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-12-12 20:37
HTTP/1.1 302 Found server: nginx date: Thu, 12 Dec 2024 20:37:14 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JEY9E1C5D37F62TRVJMYKCZE","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JEY9E1C5D37F62TRVJMYKCZE x-runtime: 0.016309 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-12-03 06:06
HTTP/1.1 302 Found server: nginx date: Tue, 03 Dec 2024 06:06:31 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JE5J18E93QZHWNZAYTEFD0CD","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JE5J18E93QZHWNZAYTEFD0CD x-runtime: 0.043330 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-12-01 01:57
HTTP/1.1 302 Found server: nginx date: Sun, 01 Dec 2024 01:57:38 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JDZZ031992RYSBXATVJ733TM","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JDZZ031992RYSBXATVJ733TM x-runtime: 0.018287 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:80 · gitlab.car-idc.no
2024-11-29 03:20
HTTP/1.1 302 Found content-length: 0 location: https://gitlab.car-idc.no/ cache-control: no-cache connection: close
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-11-29 03:20
HTTP/1.1 302 Found server: nginx date: Fri, 29 Nov 2024 03:20:15 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JDTYXXBMJXARNB2N3PK3ZT4T","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JDTYXXBMJXARNB2N3PK3ZT4T x-runtime: 0.042344 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-11-29 02:02
HTTP/1.1 302 Found server: nginx date: Fri, 29 Nov 2024 02:02:14 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JDTTF29MXCKSQ26Q52TKNGE4","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JDTTF29MXCKSQ26Q52TKNGE4 x-runtime: 0.019393 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-11-27 02:12
HTTP/1.1 302 Found server: nginx date: Wed, 27 Nov 2024 02:12:07 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JDNP7QP4TK80FCEYKY0SGK5E","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JDNP7QP4TK80FCEYKY0SGK5E x-runtime: 0.041961 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>
Open service 62.128.239.155:443 · gitlab.car-idc.no
2024-11-21 02:30
HTTP/1.1 302 Found server: nginx date: Thu, 21 Nov 2024 02:30:53 GMT content-type: text/html; charset=utf-8 content-length: 105 cache-control: no-cache content-security-policy: location: https://gitlab.car-idc.no/users/sign_in permissions-policy: interest-cohort=() x-content-type-options: nosniff x-download-options: noopen x-frame-options: SAMEORIGIN x-gitlab-meta: {"correlation_id":"01JD68XRYQMVVVB2YRD2Y6WH8A","version":"1"} x-permitted-cross-domain-policies: none x-request-id: 01JD68XRYQMVVVB2YRD2Y6WH8A x-runtime: 0.043194 x-ua-compatible: IE=edge x-xss-protection: 1; mode=block strict-transport-security: max-age=63072000 referrer-policy: strict-origin-when-cross-origin connection: close <html><body>You are being <a href="https://gitlab.car-idc.no/users/sign_in">redirected</a>.</body></html>