nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-21 02:04
HTTP/1.1 302 Found Server: nginx Date: Sat, 21 Dec 2024 02:04:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFKFAKJ88DGKCVAWHBFA5GGQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFKFAKJ88DGKCVAWHBFA5GGQ X-Runtime: 0.022464 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-19 03:17
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 03:17:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFEEPMN6PNJJ65V0JKMRPSX3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFEEPMN6PNJJ65V0JKMRPSX3 X-Runtime: 0.023542 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-14 15:52
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 15:52:51 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2XYRGW5A7WE7JKBYJCQFYC","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2XYRGW5A7WE7JKBYJCQFYC X-Runtime: 0.052356 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-12 18:13
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 18:13:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEY168KTAWK71H9FGETWV2A5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEY168KTAWK71H9FGETWV2A5 X-Runtime: 0.057207 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-02 17:09
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 17:09:03 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE45HN3EDF82CRFY92MTMZBY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE45HN3EDF82CRFY92MTMZBY X-Runtime: 0.025077 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-11-30 11:24
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 11:24:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYD0S08XF83W4BZS8HK5KCZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYD0S08XF83W4BZS8HK5KCZ X-Runtime: 0.057986 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-11-28 04:46
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 04:47:04 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRHG5MTR2S61BAW70YFGKD2","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRHG5MTR2S61BAW70YFGKD2 X-Runtime: 0.032265 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-11-21 02:15
HTTP/1.1 302 Found Server: nginx Date: Thu, 21 Nov 2024 02:15:37 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD681TZF61035HMQ0VHTEHR0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD681TZF61035HMQ0VHTEHR0 X-Runtime: 0.057452 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>