nginx
tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 125.141.133.59:80
2024-12-22 00:58
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:58:56 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXZP444PMNKV0QKEBZW84F","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXZP444PMNKV0QKEBZW84F X-Runtime: 0.043609 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>
Open service 125.141.133.59:80
2024-12-20 00:34
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:34:53 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQT7QR8QPSBPRDBCZAW5K6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQT7QR8QPSBPRDBCZAW5K6 X-Runtime: 0.018472 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>
Open service 125.141.133.59:80
2024-12-18 01:47
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 01:47:08 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBQ52B6AH5EFMY72KR4FKWG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBQ52B6AH5EFMY72KR4FKWG X-Runtime: 0.019511 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>
Open service 125.141.133.59:80
2024-12-15 23:53
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 23:53:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6BTXRQ4KVDJ9VMZSR0Q3JZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6BTXRQ4KVDJ9VMZSR0Q3JZ X-Runtime: 0.046297 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>
Open service 125.141.133.59:80
2024-12-14 00:05
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 00:05:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF17QCYAGGR8CTJCVCKP63ZJ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF17QCYAGGR8CTJCVCKP63ZJ X-Runtime: 0.018915 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>
Open service 125.141.133.59:80
2024-12-12 01:04
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 01:04:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW6B6TGHJPC9SXZC4R0P60B","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW6B6TGHJPC9SXZC4R0P60B X-Runtime: 0.048282 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>
Open service 125.141.133.59:80
2024-12-02 01:00
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 01:00:22 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2E3Y8PK76Q3F53A6DSRBZG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2E3Y8PK76Q3F53A6DSRBZG X-Runtime: 0.041529 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>
Open service 125.141.133.59:80
2024-11-30 00:32
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 00:33:00 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX7RDDBG5A3VN22E1TD9SH4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX7RDDBG5A3VN22E1TD9SH4 X-Runtime: 0.017277 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>
Open service 125.141.133.59:80
2024-11-28 00:28
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 00:28:01 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://125.141.133.59/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR2NTZDQ543TMMB10NQJSMA","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR2NTZDQ543TMMB10NQJSMA X-Runtime: 0.042911 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://125.141.133.59/users/sign_in">redirected</a>.</body></html>