nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 52.221.109.245:443
2024-12-22 01:00
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 01:00:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNY1YMPNXE8QM6JKFJCK5NY","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNY1YMPNXE8QM6JKFJCK5NY X-Runtime: 0.017684 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>
Open service 52.221.109.245:443
2024-12-20 00:32
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:32:22 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQNKVC2EVM1FXXH45H608B","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQNKVC2EVM1FXXH45H608B X-Runtime: 0.016414 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>
Open service 52.221.109.245:443
2024-12-18 01:38
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 01:38:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBPP4Z3NC31HM65YZK9MPY0","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBPP4Z3NC31HM65YZK9MPY0 X-Runtime: 0.015793 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>
Open service 52.221.109.245:443
2024-12-15 23:15
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 23:15:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF69PF46YCQYJJVT7FNR32XX","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF69PF46YCQYJJVT7FNR32XX X-Runtime: 0.015475 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>
Open service 52.221.109.245:443
2024-12-13 23:06
HTTP/1.1 302 Found Server: nginx Date: Fri, 13 Dec 2024 23:06:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF14BDQK6NAC2V88A4W7CY4Z","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF14BDQK6NAC2V88A4W7CY4Z X-Runtime: 0.021361 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>
Open service 52.221.109.245:443
2024-12-11 22:26
HTTP/1.1 302 Found Server: nginx Date: Wed, 11 Dec 2024 22:26:40 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEVX9PJ8BW5VSYBXQFAJ0PPS","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEVX9PJ8BW5VSYBXQFAJ0PPS X-Runtime: 0.016794 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>
Open service 52.221.109.245:443
2024-12-02 01:11
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 01:11:18 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2EQZ1WXPX6EXC8H6KWHDX7","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2EQZ1WXPX6EXC8H6KWHDX7 X-Runtime: 0.018856 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>
Open service 52.221.109.245:443
2024-11-30 00:46
HTTP/1.1 302 Found Server: nginx Date: Sat, 30 Nov 2024 00:46:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX8HJXPD66VW3XEAZ4NGPTG","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX8HJXPD66VW3XEAZ4NGPTG X-Runtime: 0.020038 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>
Open service 52.221.109.245:443
2024-11-28 00:38
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 00:38:38 GMT Content-Type: text/html; charset=utf-8 Content-Length: 102 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://52.221.109.245/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR398NBYHHBZ1V53XGQWB1D","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR398NBYHHBZ1V53XGQWB1D X-Runtime: 0.016316 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://52.221.109.245/users/sign_in">redirected</a>.</body></html>