nginx 1.25.1
tcp/443 tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-12-22 04:06
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Sun, 22 Dec 2024 04:06:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP8R15KANGKPWCN7AP1603M","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP8R15KANGKPWCN7AP1603M X-Runtime: 0.020254 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-12-20 05:51
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Fri, 20 Dec 2024 05:51:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFH9YVPT3EC4GV0T4H1F127K","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFH9YVPT3EC4GV0T4H1F127K X-Runtime: 0.049318 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-12-19 01:08
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Thu, 19 Dec 2024 01:08:52 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE7BQKJGD96S14HD2YF4DBX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE7BQKJGD96S14HD2YF4DBX X-Runtime: 0.022848 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:80 · gitlab.dseis.ru
2024-12-13 16:09
HTTP/1.1 301 Moved Permanently Server: nginx/1.25.1 Date: Fri, 13 Dec 2024 16:09:42 GMT Content-Type: text/html Content-Length: 169 Connection: close Location: https://gitlab.dseis.ru/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.25.1</center> </body> </html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-12-13 16:09
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Fri, 13 Dec 2024 16:09:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF0CGZE169D7TX8DRCE83SSD","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF0CGZE169D7TX8DRCE83SSD X-Runtime: 0.027337 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-12-12 16:35
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Thu, 12 Dec 2024 16:35:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXVKSPQJRX1XZPB14NJ013W","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXVKSPQJRX1XZPB14NJ013W X-Runtime: 0.048582 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-12-02 20:05
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Mon, 02 Dec 2024 20:05:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4FM6THMSHKM9EJ0TYQTBE7","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4FM6THMSHKM9EJ0TYQTBE7 X-Runtime: 0.076372 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-11-30 21:01
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Sat, 30 Nov 2024 21:01:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZE185J3HHW27T9QB3M8VCT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZE185J3HHW27T9QB3M8VCT X-Runtime: 0.052152 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-11-28 19:55
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Thu, 28 Nov 2024 19:55:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDT5G1CYDECS5AD98D01Z9QX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDT5G1CYDECS5AD98D01Z9QX X-Runtime: 0.021004 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-11-27 01:32
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Wed, 27 Nov 2024 01:32:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDNKZN48ED2AWD801X3107V6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDNKZN48ED2AWD801X3107V6 X-Runtime: 0.021275 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>
Open service 51.250.15.240:443 · gitlab.dseis.ru
2024-11-20 14:06
HTTP/1.1 302 Found Server: nginx/1.25.1 Date: Wed, 20 Nov 2024 14:07:14 GMT Content-Type: text/html; charset=utf-8 Content-Length: 103 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.dseis.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD4YC4611XKAHCGBNGHNTBDX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD4YC4611XKAHCGBNGHNTBDX X-Runtime: 0.072879 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Strict-Transport-Security: max-age=31536000 <html><body>You are being <a href="https://gitlab.dseis.ru/users/sign_in">redirected</a>.</body></html>