nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 212.24.159.37:443
2024-12-22 00:53
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:53:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNXP4GS14MNZHS5FAN7GVPF","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNXP4GS14MNZHS5FAN7GVPF X-Runtime: 0.027541 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-12-21 00:16
HTTP/1.1 302 Found Server: nginx Date: Sat, 21 Dec 2024 00:16:33 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFK95CHRNE28H89RJYCP506V","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFK95CHRNE28H89RJYCP506V X-Runtime: 0.049530 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443
2024-12-20 00:03
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:04:00 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGP1NKYDQFMMG632CSS0R5T","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGP1NKYDQFMMG632CSS0R5T X-Runtime: 0.055828 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-12-18 08:58
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 08:58:54 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFCFVNE66DZHMSSFYDPXJ4A5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFCFVNE66DZHMSSFYDPXJ4A5 X-Runtime: 0.056049 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443
2024-12-17 21:52
HTTP/1.1 302 Found Server: nginx Date: Tue, 17 Dec 2024 21:52:56 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFB9R8B6M44VP0FJVD40NP8W","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFB9R8B6M44VP0FJVD40NP8W X-Runtime: 0.053996 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-12-16 03:23
HTTP/1.1 302 Found Server: nginx Date: Mon, 16 Dec 2024 03:23:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6QVCD4C13RG48GDQC6Z26H","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6QVCD4C13RG48GDQC6Z26H X-Runtime: 0.026524 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443
2024-12-15 21:54
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 21:54:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6511G1QH9CYFKEM1SHQMFG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6511G1QH9CYFKEM1SHQMFG X-Runtime: 0.023060 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-12-14 04:15
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 04:15:40 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF1P25Y1B8BV6DJ08SD1WM83","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF1P25Y1B8BV6DJ08SD1WM83 X-Runtime: 0.022740 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443
2024-12-13 21:48
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 21:48:40 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF0ZXJD93P6BHV97196NBBSM","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF0ZXJD93P6BHV97196NBBSM X-Runtime: 0.023323 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-12-12 05:52
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 05:52:08 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEWPSBWYTQDFZA9WET1EVQG1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEWPSBWYTQDFZA9WET1EVQG1 X-Runtime: 0.023429 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443
2024-12-11 23:54
HTTP/1.1 302 Found Server: nginx Date: Wed, 11 Dec 2024 23:54:07 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW29TCKRVM90S8SJJ38JJSF","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW29TCKRVM90S8SJJ38JJSF X-Runtime: 0.034131 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-12-02 19:39
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 19:39:05 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE4E4BW8DWSBX6JZMQ3YJFPB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE4E4BW8DWSBX6JZMQ3YJFPB X-Runtime: 0.055625 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443
2024-12-01 23:42
HTTP/1.1 302 Found Server: nginx Date: Sun, 01 Dec 2024 23:42:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE29NRK23K7BAW6MTXYSVMG2","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE29NRK23K7BAW6MTXYSVMG2 X-Runtime: 0.033498 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-11-30 16:24
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 16:24:21 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDYY6CJ5TY2MGMSMZAEXYECK","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDYY6CJ5TY2MGMSMZAEXYECK X-Runtime: 0.024854 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443
2024-11-29 21:57
HTTP/1.1 302 Found Server: nginx Date: Fri, 29 Nov 2024 21:57:54 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDWYWD602SNDR2H9HF7TTABW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDWYWD602SNDR2H9HF7TTABW X-Runtime: 0.048094 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-11-28 16:12
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 16:12:11 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDSRPNR009PWYCTRA8864316","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDSRPNR009PWYCTRA8864316 X-Runtime: 0.023490 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443
2024-11-27 21:53
HTTP/1.1 302 Found Server: nginx Date: Wed, 27 Nov 2024 21:53:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://212.24.159.37/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDQSV95SA7J8BVFMCXEZA1PW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDQSV95SA7J8BVFMCXEZA1PW X-Runtime: 0.024286 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://212.24.159.37/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-11-26 16:22
HTTP/1.1 302 Found Server: nginx Date: Tue, 26 Nov 2024 16:22:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDMMFGMK2169GW683N4FACRE","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDMMFGMK2169GW683N4FACRE X-Runtime: 0.026365 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>
Open service 212.24.159.37:443 · gitlab-backup.devlab.cz
2024-11-20 17:46
HTTP/1.1 302 Found Server: nginx Date: Wed, 20 Nov 2024 17:47:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 111 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab-backup.devlab.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD5AZ0WND5HJWXPQC6J91K55","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD5AZ0WND5HJWXPQC6J91K55 X-Runtime: 0.044968 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab-backup.devlab.cz/users/sign_in">redirected</a>.</body></html>