nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 18.212.14.233:443 · quantumgitlab.ddns.net
2024-12-22 03:54
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 03:54:54 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://quantumgitlab.ddns.net/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFP81XHWGD9ZWF4Z2ATMS3GN","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFP81XHWGD9ZWF4Z2ATMS3GN X-Runtime: 0.024697 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://quantumgitlab.ddns.net/users/sign_in">redirected</a>.</body></html>
Open service 18.212.14.233:443 · quantumgitlab.ddns.net
2024-12-20 06:09
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 06:09:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://quantumgitlab.ddns.net/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFHAZE88ZJ6HEJVYZ7ZA0420","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFHAZE88ZJ6HEJVYZ7ZA0420 X-Runtime: 0.050298 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://quantumgitlab.ddns.net/users/sign_in">redirected</a>.</body></html>
Open service 18.212.14.233:443 · quantumgitlab.ddns.net
2024-12-19 00:25
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 00:25:04 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://quantumgitlab.ddns.net/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE4VH6HBQHRMTBE1YHV330G","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE4VH6HBQHRMTBE1YHV330G X-Runtime: 0.064259 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://quantumgitlab.ddns.net/users/sign_in">redirected</a>.</body></html>
Open service 18.212.14.233:443 · quantumgitlab.ddns.net
2024-12-14 10:02
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 10:03:01 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://quantumgitlab.ddns.net/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF29Y6C9FK5EP9S0CQWYQX2G","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF29Y6C9FK5EP9S0CQWYQX2G X-Runtime: 0.029680 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://quantumgitlab.ddns.net/users/sign_in">redirected</a>.</body></html>
Open service 18.212.14.233:443 · quantumgitlab.ddns.net
2024-12-13 00:35
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 00:35:31 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://quantumgitlab.ddns.net/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYQ2BWDP131T562MBRVFHDW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYQ2BWDP131T562MBRVFHDW X-Runtime: 0.048331 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://quantumgitlab.ddns.net/users/sign_in">redirected</a>.</body></html>
Open service 18.212.14.233:443 · quantumgitlab.ddns.net
2024-12-02 12:10
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 12:10:39 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://quantumgitlab.ddns.net/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE3MF8TBR6R5YG8HVKADQ2E1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE3MF8TBR6R5YG8HVKADQ2E1 X-Runtime: 0.026606 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://quantumgitlab.ddns.net/users/sign_in">redirected</a>.</body></html>
Open service 18.212.14.233:443 · quantumgitlab.ddns.net
2024-11-30 11:02
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 11:02:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://quantumgitlab.ddns.net/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYBS6PDKBFAW63J0HAD01K3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYBS6PDKBFAW63J0HAD01K3 X-Runtime: 0.030398 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://quantumgitlab.ddns.net/users/sign_in">redirected</a>.</body></html>
Open service 18.212.14.233:443 · quantumgitlab.ddns.net
2024-11-28 07:18
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 07:18:33 GMT Content-Type: text/html; charset=utf-8 Content-Length: 110 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://quantumgitlab.ddns.net/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRT5HEB4AFBSP8D8F0MXDAG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRT5HEB4AFBSP8D8F0MXDAG X-Runtime: 0.021091 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://quantumgitlab.ddns.net/users/sign_in">redirected</a>.</body></html>