nginx 1.18.0
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-12-22 04:52
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sun, 22 Dec 2024 04:53:04 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFPBCCYPPMZE6WKR3RPWK294","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFPBCCYPPMZE6WKR3RPWK294 X-Runtime: 0.040580 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-12-20 03:14
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 20 Dec 2024 03:14:15 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFH0Y1JV3CQKTZ5KRWZ6PFDV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFH0Y1JV3CQKTZ5KRWZ6PFDV X-Runtime: 0.041969 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-12-19 01:01
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 19 Dec 2024 01:01:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE6YPME99RWJ3WSF6CBPA7P","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE6YPME99RWJ3WSF6CBPA7P X-Runtime: 0.018668 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-12-14 15:58
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 14 Dec 2024 15:58:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2Y9JZF3A0MTMWA07KHP21B","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2Y9JZF3A0MTMWA07KHP21B X-Runtime: 0.070438 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-12-13 02:40
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 13 Dec 2024 02:40:57 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYY81DE1MM82HXMWZWRZ32S","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYY81DE1MM82HXMWZWRZ32S X-Runtime: 0.037114 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-12-02 19:32
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Mon, 02 Dec 2024 19:32:24 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4DR4YK7EBZRD0JSQKJ48FZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4DR4YK7EBZRD0JSQKJ48FZ X-Runtime: 0.015860 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-11-30 22:29
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 30 Nov 2024 22:29:17 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZK2JS0D2KJFH5816AFFH4A","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZK2JS0D2KJFH5816AFFH4A X-Runtime: 0.037856 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-11-28 17:26
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 28 Nov 2024 17:26:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSWY698VTHE86MGV9J60VW4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSWY698VTHE86MGV9J60VW4 X-Runtime: 0.015381 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-11-26 17:11
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Tue, 26 Nov 2024 17:11:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDMQ94B5EQHYHHVJS0TEB4DM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDMQ94B5EQHYHHVJS0TEB4DM X-Runtime: 0.052896 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>
Open service 185.149.240.46:443 · gitlab.vinogradar.info
2024-11-20 13:22
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Wed, 20 Nov 2024 13:22:18 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.vinogradar.info/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD4VSVGASMG7QYBE5PFSQDC7","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD4VSVGASMG7QYBE5PFSQDC7 X-Runtime: 0.015184 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.vinogradar.info/users/sign_in">redirected</a>.</body></html>