nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-12-22 04:25
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Sun, 22 Dec 2024 04:25:47 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP9TEPSWPJW4S7NWE4SGFSD","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP9TEPSWPJW4S7NWE4SGFSD X-Runtime: 0.041090 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-12-20 05:29
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Fri, 20 Dec 2024 05:29:57 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFH8PGBGXMG24DD239ZVHH2H","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFH8PGBGXMG24DD239ZVHH2H X-Runtime: 0.046319 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-12-19 02:07
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Thu, 19 Dec 2024 02:07:14 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFEAPKBSXEERECNJ2ZVMWZS9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFEAPKBSXEERECNJ2ZVMWZS9 X-Runtime: 0.043121 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-12-14 22:16
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Sat, 14 Dec 2024 22:16:58 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF3KY31BNJDEW0H11MPDFPQQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF3KY31BNJDEW0H11MPDFPQQ X-Runtime: 0.020248 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>
Open service 202.61.196.165:80 · gitlab.thpictures.de
2024-12-14 22:16
HTTP/1.1 404 Not Found Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Sat, 14 Dec 2024 22:16:58 GMT Content-Length: 19 Connection: close 404 page not found
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-12-14 11:39
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Sat, 14 Dec 2024 11:39:59 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2FFQST5WBQ5QY45EMJE7DM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2FFQST5WBQ5QY45EMJE7DM X-Runtime: 0.044881 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-12-12 11:48
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Thu, 12 Dec 2024 11:48:42 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXB68JMBGHZMTNHD8PQ3Z8M","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXB68JMBGHZMTNHD8PQ3Z8M X-Runtime: 0.025269 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-12-02 23:58
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Mon, 02 Dec 2024 23:58:27 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4WZ9PP5WWF0JYNW1CTGHF9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4WZ9PP5WWF0JYNW1CTGHF9 X-Runtime: 0.033248 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-11-30 17:48
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Sat, 30 Nov 2024 17:48:11 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZ2ZW5V22V9SNZR1S4RNEKP","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZ2ZW5V22V9SNZR1S4RNEKP X-Runtime: 0.019385 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>
Open service 202.61.196.165:443 · gitlab.thpictures.de
2024-11-28 13:49
HTTP/1.1 302 Found Cache-Control: no-cache Content-Length: 108 Content-Security-Policy: Content-Type: text/html; charset=utf-8 Date: Thu, 28 Nov 2024 13:49:35 GMT Location: https://gitlab.thpictures.de/users/sign_in Permissions-Policy: interest-cohort=() Referrer-Policy: strict-origin-when-cross-origin Server: nginx Strict-Transport-Security: max-age=63072000 X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSGHHZVX9ANRMFP2Z07XAYY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSGHHZVX9ANRMFP2Z07XAYY X-Runtime: 0.046876 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Connection: close <html><body>You are being <a href="https://gitlab.thpictures.de/users/sign_in">redirected</a>.</body></html>