The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-12-21 02:07
HTTP/1.1 302 Found Date: Sat, 21 Dec 2024 02:07:54 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFKFH8SDABPAWF57VEYQ2ZSM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFKFH8SDABPAWF57VEYQ2ZSM X-Runtime: 0.071724 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-12-19 15:06
HTTP/1.1 302 Found Date: Thu, 19 Dec 2024 15:06:05 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFFQ8Q2P0GZGJTQX2GPGCG1X","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFFQ8Q2P0GZGJTQX2GPGCG1X X-Runtime: 0.047643 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:80 · gitlab.tere.pl
2024-12-19 15:06
HTTP/1.1 302 Found Set-Cookie: locale=pl; Max-Age=31536000; Path=/ Location: http://test.spati.com/ Date: Thu, 19 Dec 2024 15:06:04 GMT Connection: close Transfer-Encoding: chunked
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-12-18 06:21
HTTP/1.1 302 Found Date: Wed, 18 Dec 2024 06:21:28 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFC6VD781RDMRGANPQ2G9VHT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFC6VD781RDMRGANPQ2G9VHT X-Runtime: 0.064834 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-12-16 03:19
HTTP/1.1 302 Found Date: Mon, 16 Dec 2024 03:19:39 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6QN1HWEAGM3PSJ23DQ84PF","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6QN1HWEAGM3PSJ23DQ84PF X-Runtime: 0.064513 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-12-14 05:49
HTTP/1.1 302 Found Date: Sat, 14 Dec 2024 05:49:16 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF1VDJ9HH8QF3BSV25TPZDC0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF1VDJ9HH8QF3BSV25TPZDC0 X-Runtime: 0.084019 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-12-13 00:57
HTTP/1.1 302 Found Date: Fri, 13 Dec 2024 00:57:43 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYRAZX8FYRAGB2RF0ZTJRYK","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYRAZX8FYRAGB2RF0ZTJRYK X-Runtime: 0.057523 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-12-02 22:19
HTTP/1.1 302 Found Date: Mon, 02 Dec 2024 22:19:59 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4QAZS08JY6J4Q0TCG3S705","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4QAZS08JY6J4Q0TCG3S705 X-Runtime: 0.072822 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-11-30 20:18
HTTP/1.1 302 Found Date: Sat, 30 Nov 2024 20:18:05 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZBJB0V94J762260HRH08YG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZBJB0V94J762260HRH08YG X-Runtime: 0.084196 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-11-28 20:40
HTTP/1.1 302 Found Date: Thu, 28 Nov 2024 20:40:47 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDT82F67QVEF58ESQRXCYNRD","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDT82F67QVEF58ESQRXCYNRD X-Runtime: 0.078196 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-11-27 00:39
HTTP/1.1 302 Found Date: Wed, 27 Nov 2024 00:39:29 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDNGY3E0PPKH9VZYQXNR7DQ1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDNGY3E0PPKH9VZYQXNR7DQ1 X-Runtime: 0.090203 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>
Open service 46.248.190.181:443 · gitlab.tere.pl
2024-11-20 16:06
HTTP/1.1 302 Found Date: Wed, 20 Nov 2024 16:06:48 GMT Content-Type: text/html; charset=utf-8 Transfer-Encoding: chunked Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.tere.pl/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD55726DDNVS1T7EBMHNQTKF","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD55726DDNVS1T7EBMHNQTKF X-Runtime: 0.057255 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=15724800; includeSubDomains Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.tere.pl/users/sign_in">redirected</a>.</body></html>