nginx 1.23.1
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-12-22 06:54
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Sun, 22 Dec 2024 06:54:26 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFPJAMKRB7S5M7VR2C66DSRV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFPJAMKRB7S5M7VR2C66DSRV X-Runtime: 0.024445 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-12-22 00:54
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Sun, 22 Dec 2024 00:54:52 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXR8HEQBYWCMTEJB9TH0JW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXR8HEQBYWCMTEJB9TH0JW X-Runtime: 0.053832 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-12-20 04:10
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Fri, 20 Dec 2024 04:10:31 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFH452E5ZK4WF46G70ZX9XH1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFH452E5ZK4WF46G70ZX9XH1 X-Runtime: 0.024697 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-12-20 00:23
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Fri, 20 Dec 2024 00:23:33 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQ5EWFV17DQWHRV0KTJGS6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQ5EWFV17DQWHRV0KTJGS6 X-Runtime: 0.056445 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-12-19 01:35
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Thu, 19 Dec 2024 01:35:19 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFE8W5CQZC5KT8315FVMNW9S","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFE8W5CQZC5KT8315FVMNW9S X-Runtime: 0.054412 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-12-18 01:36
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Wed, 18 Dec 2024 01:36:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBPHNPDVM3WA4RY1RYCSEG1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBPHNPDVM3WA4RY1RYCSEG1 X-Runtime: 0.066523 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-12-15 23:22
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Sun, 15 Dec 2024 23:22:27 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6A2QEF03PZWSQ3BVY93J89","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6A2QEF03PZWSQ3BVY93J89 X-Runtime: 0.064526 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-12-14 12:09
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Sat, 14 Dec 2024 12:09:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2H69F32MBSGCDWJZ7XBZFG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2H69F32MBSGCDWJZ7XBZFG X-Runtime: 0.059708 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-12-13 22:07
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Fri, 13 Dec 2024 22:07:51 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF110NS594GFG6GRS48A059E","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF110NS594GFG6GRS48A059E X-Runtime: 0.034449 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-12-12 15:09
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Thu, 12 Dec 2024 15:09:23 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXPNR309KZ3EC3Z9FJ3X1N5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXPNR309KZ3EC3Z9FJ3X1N5 X-Runtime: 0.022956 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-12-11 23:21
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Wed, 11 Dec 2024 23:21:26 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW0DZBC420GB5X7GZNFBZDV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW0DZBC420GB5X7GZNFBZDV X-Runtime: 0.067992 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-12-02 21:41
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Mon, 02 Dec 2024 21:41:39 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4N4T0N71DYDXJKT6DXYV8D","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4N4T0N71DYDXJKT6DXYV8D X-Runtime: 0.023414 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-12-01 23:22
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Sun, 01 Dec 2024 23:22:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE28G45XC29GSNDJVV8BB4C4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE28G45XC29GSNDJVV8BB4C4 X-Runtime: 0.060383 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-11-30 15:37
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Sat, 30 Nov 2024 15:37:01 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYVFPQSQP6X25QDR3GNAJ8W","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYVFPQSQP6X25QDR3GNAJ8W X-Runtime: 0.049275 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-11-29 23:26
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Fri, 29 Nov 2024 23:26:26 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX3YG68MRMQ568CVRA4K170","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX3YG68MRMQ568CVRA4K170 X-Runtime: 0.049297 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-11-28 19:08
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Thu, 28 Nov 2024 19:09:01 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDT2TEETGBQ9M1150807YDDZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDT2TEETGBQ9M1150807YDDZ X-Runtime: 0.023466 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443
2024-11-27 23:59
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Wed, 27 Nov 2024 23:59:40 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://157.245.69.12/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR11XYEY5QFP34BDHPM1T1W","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR11XYEY5QFP34BDHPM1T1W X-Runtime: 0.062956 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-11-26 22:13
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Tue, 26 Nov 2024 22:13:34 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDN8JY9J8B44E70JQ4CGMCPQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDN8JY9J8B44E70JQ4CGMCPQ X-Runtime: 0.082860 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>
Open service 157.245.69.12:443 · gitlab.pav.sh
2024-11-20 14:00
HTTP/1.1 302 Found Server: nginx/1.23.1 Date: Wed, 20 Nov 2024 14:00:02 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://gitlab.pav.sh/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD4XYXRDJVRC837CEKMYMYEK","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD4XYXRDJVRC837CEKMYMYEK X-Runtime: 0.052021 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://10.147.18.203/users/sign_in">redirected</a>.</body></html>