nginx 1.14.2
tcp/443 tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-12-21 17:26
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Sat, 21 Dec 2024 17:26:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFN42N2ABPJ9ME8TMCGWDBJJ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFN42N2ABPJ9ME8TMCGWDBJJ X-Runtime: 0.058641 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Sat, 21 Dec 2024 17:26:09 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>
Open service 148.251.79.239:80 · gitlab.ontando.ru
2024-12-21 17:26
HTTP/1.1 301 Moved Permanently Server: nginx/1.14.2 Date: Sat, 21 Dec 2024 17:26:09 GMT Content-Type: text/html Content-Length: 185 Connection: close Location: https://gitlab.ontando.ru/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body bgcolor="white"> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.14.2</center> </body> </html>
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-12-21 00:34
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Sat, 21 Dec 2024 00:34:25 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFKA63E057NQ7G3E03HPTAQG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFKA63E057NQ7G3E03HPTAQG X-Runtime: 0.059186 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Sat, 21 Dec 2024 00:34:24 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-12-19 01:10
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Thu, 19 Dec 2024 01:10:36 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE7EXCX4ZXMBH0B0ZY7KTB4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE7EXCX4ZXMBH0B0ZY7KTB4 X-Runtime: 0.059825 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Thu, 19 Dec 2024 01:10:35 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-12-14 09:32
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Sat, 14 Dec 2024 09:32:11 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF285QAR8NS8DFQ7EG8HXS1J","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF285QAR8NS8DFQ7EG8HXS1J X-Runtime: 0.049639 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Sat, 14 Dec 2024 09:32:10 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-12-12 13:36
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Thu, 12 Dec 2024 13:36:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXHC57J4S74VJ65MX1B50PZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXHC57J4S74VJ65MX1B50PZ X-Runtime: 0.066397 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Thu, 12 Dec 2024 13:36:45 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-12-02 12:48
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Mon, 02 Dec 2024 12:49:00 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE3PNGB0XX54P85NFKTR8NP2","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE3PNGB0XX54P85NFKTR8NP2 X-Runtime: 0.048948 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Mon, 02 Dec 2024 12:48:59 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-11-30 10:34
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Sat, 30 Nov 2024 10:34:57 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYA6K6279NTZHFNCGQE1Z97","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYA6K6279NTZHFNCGQE1Z97 X-Runtime: 0.019875 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Sat, 30 Nov 2024 10:34:56 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-11-28 06:35
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Thu, 28 Nov 2024 06:35:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRQQK9QR9D21JGAPVRGGGX1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRQQK9QR9D21JGAPVRGGGX1 X-Runtime: 0.065321 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Thu, 28 Nov 2024 06:35:58 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>
Open service 148.251.79.239:443 · gitlab.ontando.ru
2024-11-20 20:35
HTTP/1.1 302 Found Server: nginx/1.14.2 Date: Wed, 20 Nov 2024 20:35:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 105 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.ontando.ru/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD5MKTK7JE3NHBSXGYJEYG6H","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD5MKTK7JE3NHBSXGYJEYG6H X-Runtime: 0.021236 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Expires: Wed, 20 Nov 2024 20:35:54 GMT <html><body>You are being <a href="https://gitlab.ontando.ru/users/sign_in">redirected</a>.</body></html>