nginx
tcp/443
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
WARNING: This plugin will generate false positive and is purely informative:
regreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems (CVE-2024-6387)
Severity: info
Fingerprint: 3f43e0ebb5dce37ab8b59eb50006c01bfe916ff6fe916ff6fe916ff6fe916ff6
Found potentially vulnerable SSH version: SSH-2.0-OpenSSH_8.7 WARNING, RISK IS ESTIMATED FALSE POSITIVE ARE LIKELY
Open service 54.247.240.4:443
2024-12-22 00:59
HTTP/1.1 302 Found Server: nginx Date: Sun, 22 Dec 2024 00:59:45 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNY16N2R7RNH08W8VXZJS6B","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNY16N2R7RNH08W8VXZJS6B X-Runtime: 0.050443 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443 · gitlab.gauabhij.people.aws.dev
2024-12-20 18:11
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 18:11:41 GMT Content-Type: text/html; charset=utf-8 Content-Length: 118 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.gauabhij.people.aws.dev/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFJM99QAFZD4FE4TZ5RFQDPB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFJM99QAFZD4FE4TZ5RFQDPB X-Runtime: 0.019104 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.gauabhij.people.aws.dev/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443
2024-12-20 00:34
HTTP/1.1 302 Found Server: nginx Date: Fri, 20 Dec 2024 00:34:15 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQS2BKBXPVD219WBK91WXV","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQS2BKBXPVD219WBK91WXV X-Runtime: 0.048940 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443 · gitlab.gauabhij.people.aws.dev
2024-12-18 21:24
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 21:24:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 118 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.gauabhij.people.aws.dev/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFDTH9YFG8HSHAJ5ENB0T3E6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFDTH9YFG8HSHAJ5ENB0T3E6 X-Runtime: 0.021523 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.gauabhij.people.aws.dev/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443
2024-12-18 01:46
HTTP/1.1 302 Found Server: nginx Date: Wed, 18 Dec 2024 01:46:10 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBQ39Q95G0VC5ASY05267CW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBQ39Q95G0VC5ASY05267CW X-Runtime: 0.018897 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443
2024-12-15 23:47
HTTP/1.1 302 Found Server: nginx Date: Sun, 15 Dec 2024 23:47:25 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6BGEE518GBZ986W4N8D9W5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6BGEE518GBZ986W4N8D9W5 X-Runtime: 0.044387 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443 · gitlab.gauabhij.people.aws.dev
2024-12-14 07:55
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 07:55:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 118 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.gauabhij.people.aws.dev/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF22N7BPEY6RKJAQS8VRXP0B","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF22N7BPEY6RKJAQS8VRXP0B X-Runtime: 0.047047 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.gauabhij.people.aws.dev/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443
2024-12-14 00:02
HTTP/1.1 302 Found Server: nginx Date: Sat, 14 Dec 2024 00:02:57 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF17KE4MY9XQEAEKFNH7GY1E","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF17KE4MY9XQEAEKFNH7GY1E X-Runtime: 0.046557 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443 · gitlab.gauabhij.people.aws.dev
2024-12-12 15:50
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 15:50:12 GMT Content-Type: text/html; charset=utf-8 Content-Length: 118 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.gauabhij.people.aws.dev/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEXS0FHP86JVRPPAHVN8A741","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEXS0FHP86JVRPPAHVN8A741 X-Runtime: 0.046714 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.gauabhij.people.aws.dev/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443
2024-12-12 00:55
HTTP/1.1 302 Found Server: nginx Date: Thu, 12 Dec 2024 00:55:52 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW5TWR8XH131DVW3V818YG1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW5TWR8XH131DVW3V818YG1 X-Runtime: 0.046809 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443 · gitlab.gauabhij.people.aws.dev
2024-12-03 01:52
HTTP/1.1 302 Found Server: nginx Date: Tue, 03 Dec 2024 01:52:00 GMT Content-Type: text/html; charset=utf-8 Content-Length: 118 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.gauabhij.people.aws.dev/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE53F79T906YVRWGJ3T791C9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE53F79T906YVRWGJ3T791C9 X-Runtime: 0.018730 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.gauabhij.people.aws.dev/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443
2024-12-02 00:58
HTTP/1.1 302 Found Server: nginx Date: Mon, 02 Dec 2024 00:58:50 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2E150NC9RD0BYTHZV1QR6H","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2E150NC9RD0BYTHZV1QR6H X-Runtime: 0.050138 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443 · gitlab.gauabhij.people.aws.dev
2024-12-01 00:57
HTTP/1.1 302 Found Server: nginx Date: Sun, 01 Dec 2024 00:57:57 GMT Content-Type: text/html; charset=utf-8 Content-Length: 118 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.gauabhij.people.aws.dev/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZVJT22DYNWQRW20NBPTYGE","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZVJT22DYNWQRW20NBPTYGE X-Runtime: 0.046922 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.gauabhij.people.aws.dev/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443
2024-11-29 23:41
HTTP/1.1 302 Found Server: nginx Date: Fri, 29 Nov 2024 23:41:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX4T81QM8MJZPFGM0FRNV3T","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX4T81QM8MJZPFGM0FRNV3T X-Runtime: 0.047789 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443 · gitlab.gauabhij.people.aws.dev
2024-11-28 19:53
HTTP/1.1 302 Found Server: nginx Date: Thu, 28 Nov 2024 19:53:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 118 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.gauabhij.people.aws.dev/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDT5BF7ZB1EAAZSGMFHY2148","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDT5BF7ZB1EAAZSGMFHY2148 X-Runtime: 0.043966 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.gauabhij.people.aws.dev/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443
2024-11-27 23:43
HTTP/1.1 302 Found Server: nginx Date: Wed, 27 Nov 2024 23:43:29 GMT Content-Type: text/html; charset=utf-8 Content-Length: 100 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://54.247.240.4/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR049MGF8PGQVEFW4Q5F45H","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR049MGF8PGQVEFW4Q5F45H X-Runtime: 0.048969 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://54.247.240.4/users/sign_in">redirected</a>.</body></html>
Open service 54.247.240.4:443 · gitlab.gauabhij.people.aws.dev
2024-11-21 01:50
HTTP/1.1 302 Found Server: nginx Date: Thu, 21 Nov 2024 01:50:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 118 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: https://gitlab.gauabhij.people.aws.dev/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD66KX6JA92CPK6ZJWMMS338","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD66KX6JA92CPK6ZJWMMS338 X-Runtime: 0.051145 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://gitlab.gauabhij.people.aws.dev/users/sign_in">redirected</a>.</body></html>