Apache 2.4.62
tcp/80
nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-12-22 04:01
HTTP/1.1 302 Found Date: Sun, 22 Dec 2024 04:01:26 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP8DVXSJV0KHE9EQJ5C1FVM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP8DVXSJV0KHE9EQJ5C1FVM X-Runtime: 0.173969 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-12-20 05:59
HTTP/1.1 302 Found Date: Fri, 20 Dec 2024 05:59:50 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFHAD76S34CST6X3EP5W4AVX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFHAD76S34CST6X3EP5W4AVX X-Runtime: 0.210614 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-12-19 00:53
HTTP/1.1 302 Found Date: Thu, 19 Dec 2024 00:53:41 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE6FY4S4BSV5BFYECB88T3T","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE6FY4S4BSV5BFYECB88T3T X-Runtime: 0.140737 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-12-14 15:52
HTTP/1.1 302 Found Date: Sat, 14 Dec 2024 15:52:49 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2XYPPBRKWCZDPJ6HTYZNA1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2XYPPBRKWCZDPJ6HTYZNA1 X-Runtime: 0.124037 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-12-13 21:23
HTTP/1.1 302 Found Date: Fri, 13 Dec 2024 21:23:44 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF0YFWQ0B29J3586N9FQJ37T","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF0YFWQ0B29J3586N9FQJ37T X-Runtime: 0.145868 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:80 · gitlab.vepe.fr
2024-12-13 21:23
HTTP/1.1 301 Moved Permanently Date: Fri, 13 Dec 2024 21:23:41 GMT Server: Apache/2.4.62 (Debian) Location: https://gitlab.vepe.fr/ Content-Length: 311 Connection: close Content-Type: text/html; charset=iso-8859-1 Page title: 301 Moved Permanently <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"> <html><head> <title>301 Moved Permanently</title> </head><body> <h1>Moved Permanently</h1> <p>The document has moved <a href="https://gitlab.vepe.fr/">here</a>.</p> <hr> <address>Apache/2.4.62 (Debian) Server at gitlab.vepe.fr Port 80</address> </body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-12-12 18:13
HTTP/1.1 302 Found Date: Thu, 12 Dec 2024 18:13:20 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEY16HS8VWA6AYMT7PYT8TV6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEY16HS8VWA6AYMT7PYT8TV6 X-Runtime: 0.138263 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-12-02 16:52
HTTP/1.1 302 Found Date: Mon, 02 Dec 2024 16:52:28 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE44K9MZFZTT7FSSD7YZJSXS","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE44K9MZFZTT7FSSD7YZJSXS X-Runtime: 0.156751 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-11-30 11:44
HTTP/1.1 302 Found Date: Sat, 30 Nov 2024 11:44:28 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYE5X43JNYFG32CWMF0MJF7","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYE5X43JNYFG32CWMF0MJF7 X-Runtime: 0.158319 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-11-28 04:19
HTTP/1.1 302 Found Date: Thu, 28 Nov 2024 04:19:44 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRFY3M54J15RG0FK7YYBKMK","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRFY3M54J15RG0FK7YYBKMK X-Runtime: 0.182922 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>
Open service 37.187.112.206:443 · gitlab.vepe.fr
2024-11-20 16:44
HTTP/1.1 302 Found Date: Wed, 20 Nov 2024 16:44:27 GMT Server: nginx Content-Type: text/html; charset=utf-8 Content-Length: 101 Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.vepe.fr/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD57BZZ8F47H7DGNBZ15V6EN","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD57BZZ8F47H7DGNBZ15V6EN X-Runtime: 0.159350 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin Connection: close <html><body>You are being <a href="http://gitlab.vepe.fr/users/sign_in">redirected</a>.</body></html>