nginx 1.18.0
tcp/443 tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 65.108.224.246:443
2024-12-21 22:22
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 21 Dec 2024 22:22:54 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNN1ZQ5K3XKW653GQS20WD9","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNN1ZQ5K3XKW653GQS20WD9 X-Runtime: 0.028697 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-12-21 10:05
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 21 Dec 2024 10:05:36 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFMAVZ7ARG7V7P13S6504695","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFMAVZ7ARG7V7P13S6504695 X-Runtime: 0.012390 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:80 · gitlab.digitalwish.cz
2024-12-21 10:05
HTTP/1.1 301 Moved Permanently Server: nginx/1.18.0 (Ubuntu) Date: Sat, 21 Dec 2024 10:05:35 GMT Content-Type: text/html Content-Length: 178 Connection: close Location: https://gitlab.digitalwish.cz/ Page title: 301 Moved Permanently <html> <head><title>301 Moved Permanently</title></head> <body> <center><h1>301 Moved Permanently</h1></center> <hr><center>nginx/1.18.0 (Ubuntu)</center> </body> </html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-12-20 18:56
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 20 Dec 2024 18:56:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFJPVD6607KV8TD9PXBKYSTQ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFJPVD6607KV8TD9PXBKYSTQ X-Runtime: 0.012762 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-12-20 00:45
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 20 Dec 2024 00:45:48 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGRE79BN0V72AJ4SMNCVWJ8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGRE79BN0V72AJ4SMNCVWJ8 X-Runtime: 0.038330 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-12-18 21:51
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Wed, 18 Dec 2024 21:51:16 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFDW1XQ5R4HKPE0QXWB9MW6S","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFDW1XQ5R4HKPE0QXWB9MW6S X-Runtime: 0.053929 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-12-18 01:20
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Wed, 18 Dec 2024 01:20:09 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBNKNZ77FPVAXKTFVTMVFF8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBNKNZ77FPVAXKTFVTMVFF8 X-Runtime: 0.030025 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-12-16 00:02
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Mon, 16 Dec 2024 00:02:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6CCJBM417A8Q5H990QXG7A","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6CCJBM417A8Q5H990QXG7A X-Runtime: 0.035842 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-12-13 23:44
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 13 Dec 2024 23:44:08 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF16H03FW4WV6TARN2VV7851","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF16H03FW4WV6TARN2VV7851 X-Runtime: 0.034705 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-12-12 21:49
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 12 Dec 2024 21:49:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEYDK8D0APQTWPRXWYPF27WN","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEYDK8D0APQTWPRXWYPF27WN X-Runtime: 0.013074 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-12-12 00:41
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 12 Dec 2024 00:41:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW51071H4NCE4XZH0WPQ26R","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW51071H4NCE4XZH0WPQ26R X-Runtime: 0.020930 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-12-02 18:19
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Mon, 02 Dec 2024 18:19:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE49K66E126JC1RPHV9X951M","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE49K66E126JC1RPHV9X951M X-Runtime: 0.038816 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-12-02 00:52
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Mon, 02 Dec 2024 00:52:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2DPDS34QCJAF68P0DS4RWW","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2DPDS34QCJAF68P0DS4RWW X-Runtime: 0.012171 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-11-30 18:11
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 30 Nov 2024 18:11:42 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDZ4AXSMY1YD3240PGW8RQ3K","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDZ4AXSMY1YD3240PGW8RQ3K X-Runtime: 0.015006 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-11-29 22:03
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 29 Nov 2024 22:03:29 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDWZ6MNKXVBTFYNXEX3VYYV3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDWZ6MNKXVBTFYNXEX3VYYV3 X-Runtime: 0.026351 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-11-28 09:58
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 28 Nov 2024 09:58:59 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDS3B9V5J7CTAT775QVVPW17","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDS3B9V5J7CTAT775QVVPW17 X-Runtime: 0.014239 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-11-28 00:12
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 28 Nov 2024 00:13:00 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR1TAZTM0719EG8MJMHPM8V","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR1TAZTM0719EG8MJMHPM8V X-Runtime: 0.045982 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-11-26 18:44
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Tue, 26 Nov 2024 18:44:47 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDMWMMADCBY4GWCBQY08FD50","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDMWMMADCBY4GWCBQY08FD50 X-Runtime: 0.013870 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443 · gitlab.digitalwish.cz
2024-11-20 22:54
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Wed, 20 Nov 2024 22:54:25 GMT Content-Type: text/html; charset=utf-8 Content-Length: 108 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://gitlab.digitalwish.cz/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD5WHD63H5BAP8EJM2AZR8TK","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD5WHD63H5BAP8EJM2AZR8TK X-Runtime: 0.036171 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://gitlab.digitalwish.cz/users/sign_in">redirected</a>.</body></html>
Open service 65.108.224.246:443
2024-11-20 08:56
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Wed, 20 Nov 2024 08:56:35 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Connection: close Cache-Control: no-cache Content-Security-Policy: Location: http://65.108.224.246/users/sign_in Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JD4CKA37MMPP946AGTQCVMZE","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JD4CKA37MMPP946AGTQCVMZE X-Runtime: 0.029299 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="http://65.108.224.246/users/sign_in">redirected</a>.</body></html>