nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-12-22 04:10
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 04:10:29 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP8YDZ96JWWEVMRYA34PDQA","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP8YDZ96JWWEVMRYA34PDQA X-Runtime: 0.053307 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-12-20 05:46
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 05:46:52 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFH9NF5CXM3Y0A7SY9RF75KM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFH9NF5CXM3Y0A7SY9RF75KM X-Runtime: 0.058376 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-12-19 01:15
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 01:15:06 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE7Q4PP0G81NM6G349G7YPG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE7Q4PP0G81NM6G349G7YPG X-Runtime: 0.047647 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-12-14 10:11
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 10:11:13 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2AD6TKVNRH5P927WEC92H0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2AD6TKVNRH5P927WEC92H0 X-Runtime: 0.042985 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-12-13 00:13
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 00:13:34 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYNT5BE5WDD30MG1RCGAKDP","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYNT5BE5WDD30MG1RCGAKDP X-Runtime: 0.042595 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-12-02 12:35
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 12:35:52 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE3NXEBAD17KHYXFJ9HT6JP3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE3NXEBAD17KHYXFJ9HT6JP3 X-Runtime: 0.111070 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-11-30 10:44
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 10:44:03 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYAQ91TZX634B837CJ4C5EE","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYAQ91TZX634B837CJ4C5EE X-Runtime: 0.120410 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-11-28 08:04
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 08:04:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRWTE6T8GZN2P0439ADKM4H","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRWTE6T8GZN2P0439ADKM4H X-Runtime: 0.091330 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>
Open service 217.20.138.59:443 · gitlab.sys.h3.hu
2024-11-21 02:09
HTTP/1.1 302 Found Server: nginx Date: Thu, 21 Nov 2024 02:09:18 GMT Content-Type: text/html; charset=utf-8 Content-Length: 104 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.sys.h3.hu/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD67P8Z31BRY1YD7GAKYH7EA","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD67P8Z31BRY1YD7GAKYH7EA X-Runtime: 0.108443 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin X-Robots-Tag: noindex, nofollow Strict-Transport-Security: max-age=15552000 <html><body>You are being <a href="https://gitlab.sys.h3.hu/users/sign_in">redirected</a>.</body></html>