The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-12-22 04:53
HTTP/1.1 302 Found Date: Sun, 22 Dec 2024 04:54:01 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFPBE4HMAKYCWPW3T81JK483","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFPBE4HMAKYCWPW3T81JK483 X-Runtime: 0.057761 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-12-20 01:33
HTTP/1.1 302 Found Date: Fri, 20 Dec 2024 01:33:39 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGV5TH2NM4HRR1MVYXC56RQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGV5TH2NM4HRR1MVYXC56RQ X-Runtime: 0.047425 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-12-18 11:02
HTTP/1.1 302 Found Date: Wed, 18 Dec 2024 11:02:14 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFCPXGKFDC12A1EPHFDZKHG8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFCPXGKFDC12A1EPHFDZKHG8 X-Runtime: 0.028788 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-12-14 15:11
HTTP/1.1 302 Found Date: Sat, 14 Dec 2024 15:11:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2VJG8VAN9TC0KS7FNBYSHW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2VJG8VAN9TC0KS7FNBYSHW X-Runtime: 0.026284 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-12-12 16:21
HTTP/1.1 302 Found Date: Thu, 12 Dec 2024 16:21:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXTT5SRW1GA88J7MY63P7ES","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXTT5SRW1GA88J7MY63P7ES X-Runtime: 0.040185 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-12-02 06:37
HTTP/1.1 302 Found Date: Mon, 02 Dec 2024 06:37:31 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE31D9S13SND2X8KFA8H01WH","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE31D9S13SND2X8KFA8H01WH X-Runtime: 0.099190 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-11-30 04:00
HTTP/1.1 302 Found Date: Sat, 30 Nov 2024 04:00:14 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDXKKVBWP3P625AAD9PSZSTQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDXKKVBWP3P625AAD9PSZSTQ X-Runtime: 0.110211 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-11-28 21:52
HTTP/1.1 302 Found Date: Thu, 28 Nov 2024 21:52:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDTC5Y9AEER160TDYG3QWHAB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDTC5Y9AEER160TDYG3QWHAB X-Runtime: 0.066347 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-11-26 21:06
HTTP/1.1 302 Found Date: Tue, 26 Nov 2024 21:06:06 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDN4QCXR03F7BTTYEBJ9107N","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDN4QCXR03F7BTTYEBJ9107N X-Runtime: 0.089993 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>
Open service 188.94.153.58:443 · gitlab.nls.kz
2024-11-21 00:52
HTTP/1.1 302 Found Date: Thu, 21 Nov 2024 00:52:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.nls.kz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD63A039523B52ABMN383WC9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD63A039523B52ABMN383WC9 X-Runtime: 0.128659 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.nls.kz/users/sign_in">redirected</a>.</body></html>