nginx
tcp/443 tcp/8090
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 182.23.140.35:443
2024-12-22 00:55
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:54:31 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXQKH90BW3M9MB5X6TGYJP","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXQKH90BW3M9MB5X6TGYJP X-Runtime: 0.045300 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-12-20 13:50
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 13:49:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFJ59JFX70RWY5J000WES04W","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFJ59JFX70RWY5J000WES04W X-Runtime: 0.104419 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443
2024-12-20 00:27
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:26:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQB7NZKMXFAD4BNS0RWS2Q","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQB7NZKMXFAD4BNS0RWS2Q X-Runtime: 0.120669 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-12-18 13:15
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 13:14:23 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFCYFF44926ZSH0P29GVD8ND","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFCYFF44926ZSH0P29GVD8ND X-Runtime: 0.051513 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443
2024-12-18 01:30
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 01:29:49 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBP5CC5GQP3PW7Q3W1VV4DS","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBP5CC5GQP3PW7Q3W1VV4DS X-Runtime: 0.110157 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:8090
2024-12-17 19:35
HTTP/1.1 200 OK Server: nginx Date: Tue, 17 Dec 2024 19:34:39 GMT Content-Length: 0 Connection: close Cache-Control: no-cache Strict-Transport-Security: max-age=63072000
Open service 182.23.140.35:443
2024-12-15 23:13
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 23:13:08 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF69HNEYZN9NGKXMBKT6TNGW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF69HNEYZN9NGKXMBKT6TNGW X-Runtime: 0.114632 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-12-14 14:42
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 14:42:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF2SX7VEMNFHE7R2YQT1V4CP","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF2SX7VEMNFHE7R2YQT1V4CP X-Runtime: 0.113295 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443
2024-12-13 23:09
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 23:08:55 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF14GGE2XMCDGZ77BBRQCXGE","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF14GGE2XMCDGZ77BBRQCXGE X-Runtime: 0.114267 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-12-12 12:20
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 12:20:23 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXD09DW1V4FQR71BN650T9F","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXD09DW1V4FQR71BN650T9F X-Runtime: 0.045267 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443
2024-12-11 21:46
HTTP/1.1 302 Found Server: nginx Date: Wed, 11 Dec 2024 21:45:33 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEVTYDFJM00E2Q67CE773Z06","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEVTYDFJM00E2Q67CE773Z06 X-Runtime: 0.041686 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-12-02 09:52
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 09:51:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE3CGWPSZCDFBHYMPF9KEA0R","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE3CGWPSZCDFBHYMPF9KEA0R X-Runtime: 0.047424 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443
2024-12-02 01:25
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 01:24:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2FGK1R25THK2VZM35VHDP2","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2FGK1R25THK2VZM35VHDP2 X-Runtime: 0.035472 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-11-30 07:22
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 07:22:38 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDXZ6EPS8GH3YKZDN8YEH7D4","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDXZ6EPS8GH3YKZDN8YEH7D4 X-Runtime: 0.097426 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443
2024-11-30 00:40
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 00:39:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX84SZ8S98JYQFGXGPM628W","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX84SZ8S98JYQFGXGPM628W X-Runtime: 0.101337 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-11-28 23:54
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 23:54:06 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDTK4E872DDTK6985A2D7AGZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDTK4E872DDTK6985A2D7AGZ X-Runtime: 0.112750 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443
2024-11-28 00:06
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 00:06:02 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://182.23.140.35/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR1DJSGKFYM26JZTMZD9ECG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR1DJSGKFYM26JZTMZD9ECG X-Runtime: 0.141511 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://182.23.140.35/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-11-26 22:46
HTTP/1.1 302 Found Server: nginx Date: Tue, 26 Nov 2024 22:46:22 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDNAF0DF6D4PRPXXWNHSDC01","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDNAF0DF6D4PRPXXWNHSDC01 X-Runtime: 0.100010 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>
Open service 182.23.140.35:443 · codehub.onmobile.com
2024-11-21 00:26
HTTP/1.1 302 Found Server: nginx Date: Thu, 21 Nov 2024 00:26:49 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://codehub.onmobile.com/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD61TM4W7QHNBFMBY5VG2G76","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD61TM4W7QHNBFMBY5VG2G76 X-Runtime: 0.099594 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://codehub.onmobile.com/users/sign_in">redirected</a>.</body></html>