nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 147.91.12.232:443
2024-12-21 21:42
HTTP/1.1 302 Found Server: nginx Date: Sat, 21 Dec 2024 21:42:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNJR58Z488WTFFQ832JAJDF","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNJR58Z488WTFFQ832JAJDF X-Runtime: 0.070833 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-21 02:04
HTTP/1.1 302 Found Server: nginx Date: Sat, 21 Dec 2024 02:04:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFKFAKJ88DGKCVAWHBFA5GGQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFKFAKJ88DGKCVAWHBFA5GGQ X-Runtime: 0.022464 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443
2024-12-19 21:38
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 21:38:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGDQKY3N0WWJ9N76A2PXWEM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGDQKY3N0WWJ9N76A2PXWEM X-Runtime: 0.024850 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-19 03:17
HTTP/1.1 302 Found Server: nginx Date: Thu, 19 Dec 2024 03:17:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFEEPMN6PNJJ65V0JKMRPSX3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFEEPMN6PNJJ65V0JKMRPSX3 X-Runtime: 0.023542 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443
2024-12-17 22:11
HTTP/1.1 302 Found Server: nginx Date: Tue, 17 Dec 2024 22:11:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBAV3VGMDE1FYVY751R6QF7","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBAV3VGMDE1FYVY751R6QF7 X-Runtime: 0.068806 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443
2024-12-15 21:40
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 21:40:13 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF647GJS4KF60Q04ANPC736X","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF647GJS4KF60Q04ANPC736X X-Runtime: 0.024028 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-14 15:52
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 15:52:51 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2XYRGW5A7WE7JKBYJCQFYC","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2XYRGW5A7WE7JKBYJCQFYC X-Runtime: 0.052356 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443
2024-12-13 22:35
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 22:35:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF12JWJ6812YVJBZS3S7Y5SB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF12JWJ6812YVJBZS3S7Y5SB X-Runtime: 0.070984 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-12 18:13
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 18:13:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEY168KTAWK71H9FGETWV2A5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEY168KTAWK71H9FGETWV2A5 X-Runtime: 0.057207 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443
2024-12-11 22:31
HTTP/1.1 302 Found Server: nginx Date: Wed, 11 Dec 2024 22:31:39 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEVXJTQMM1G0073K9DQAYPBQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEVXJTQMM1G0073K9DQAYPBQ X-Runtime: 0.024669 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-12-02 17:09
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 17:09:03 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE45HN3EDF82CRFY92MTMZBY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE45HN3EDF82CRFY92MTMZBY X-Runtime: 0.025077 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443
2024-12-01 21:40
HTTP/1.1 302 Found Server: nginx Date: Sun, 01 Dec 2024 21:40:49 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE22PJND8RMY45Q35YXZADPY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE22PJND8RMY45Q35YXZADPY X-Runtime: 0.022115 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-11-30 11:24
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 11:24:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYD0S08XF83W4BZS8HK5KCZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYD0S08XF83W4BZS8HK5KCZ X-Runtime: 0.057986 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443
2024-11-29 21:15
HTTP/1.1 302 Found Server: nginx Date: Fri, 29 Nov 2024 21:15:17 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDWWEBXNVHE937XCQ7ABHGA7","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDWWEBXNVHE937XCQ7ABHGA7 X-Runtime: 0.050572 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-11-28 04:46
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 04:47:04 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDRHG5MTR2S61BAW70YFGKD2","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDRHG5MTR2S61BAW70YFGKD2 X-Runtime: 0.032265 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443
2024-11-27 21:20
HTTP/1.1 302 Found Server: nginx Date: Wed, 27 Nov 2024 21:20:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://147.91.12.232/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDQQZ0F44NRRCXGKSGHFACTT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDQQZ0F44NRRCXGKSGHFACTT X-Runtime: 0.018183 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://147.91.12.232/users/sign_in">redirected</a>.</body></html>
Open service 147.91.12.232:443 · rtidev2.etf.bg.ac.rs
2024-11-21 02:15
HTTP/1.1 302 Found Server: nginx Date: Thu, 21 Nov 2024 02:15:37 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://rtidev2.etf.bg.ac.rs/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD681TZF61035HMQ0VHTEHR0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD681TZF61035HMQ0VHTEHR0 X-Runtime: 0.057452 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://rtidev2.etf.bg.ac.rs/users/sign_in">redirected</a>.</body></html>