nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-22 01:55
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 01:55:31 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP17A4K7AQBFRTN1ZD2HC8W","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP17A4K7AQBFRTN1ZD2HC8W X-Runtime: 0.035480 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-20 15:54
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 15:54:21 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFJCDTHZ6YYKXND2DFJ19JF9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFJCDTHZ6YYKXND2DFJ19JF9 X-Runtime: 0.037256 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-20 02:42
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 02:42:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGZ4SM4J4422SEJYHC41T69","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGZ4SM4J4422SEJYHC41T69 X-Runtime: 0.030867 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-18 23:14
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 23:14:51 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE0TZB5265E12TMA9XZD4EW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE0TZB5265E12TMA9XZD4EW X-Runtime: 0.041894 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-18 03:30
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 03:30:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBX1XVHN5AA3FH3DTMBRVEN","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBX1XVHN5AA3FH3DTMBRVEN X-Runtime: 0.043570 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-16 01:12
HTTP/1.1 302 Found Server: nginx Date: Mon, 16 Dec 2024 01:12:27 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6GC4FQFBPJB5SWRGEK4VQ5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6GC4FQFBPJB5SWRGEK4VQ5 X-Runtime: 0.016984 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-14 09:56
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 09:56:50 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF29JVSK1ZE8912HKCE4VZ7X","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF29JVSK1ZE8912HKCE4VZ7X X-Runtime: 0.019769 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-14 01:02
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 01:02:04 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF1AZPKKY768VYT50MJEK1M3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF1AZPKKY768VYT50MJEK1M3 X-Runtime: 0.022438 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-12 15:43
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 15:43:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXRM8SWSRTWYNA4CBGZP7YW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXRM8SWSRTWYNA4CBGZP7YW X-Runtime: 0.043718 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-12 02:25
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 02:25:00 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEWAY3CF996NFYDQBPZGK4S9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEWAY3CF996NFYDQBPZGK4S9 X-Runtime: 0.017626 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-03 01:03
HTTP/1.1 302 Found Server: nginx Date: Tue, 03 Dec 2024 01:03:56 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE50Q6H864THNFWT18EY8KTK","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE50Q6H864THNFWT18EY8KTK X-Runtime: 0.044647 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-12-02 04:24
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 04:24:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2SS147PMRBV337KAYP78JC","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2SS147PMRBV337KAYP78JC X-Runtime: 0.017431 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-11-30 11:37
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 11:37:21 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYDRVANAT8903S4B831VK37","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYDRVANAT8903S4B831VK37 X-Runtime: 0.033365 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-11-30 02:44
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 02:44:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDXF9Q5990JF1KYCEXCGYNT6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDXF9Q5990JF1KYCEXCGYNT6 X-Runtime: 0.024941 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-11-28 10:13
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 10:13:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDS45YP79NVQGZKJHPFDYVP5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDS45YP79NVQGZKJHPFDYVP5 X-Runtime: 0.015868 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-11-28 02:59
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 02:59:30 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRBB71WWZV0DB89AA689FAW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRBB71WWZV0DB89AA689FAW X-Runtime: 0.015550 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>
Open service 168.119.107.10:443 · kiga-straphael-rot.de
2024-11-20 11:08
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 11:08:21 GMT Content-Type: text/html; charset=utf-8 Content-Length: 109 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://kiga-straphael-rot.de/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD4M4K0EJWQW2K9N6CBPD8V5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD4M4K0EJWQW2K9N6CBPD8V5 X-Runtime: 0.016824 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://kiga-straphael-rot.de/users/sign_in">redirected</a>.</body></html>