nginx 1.18.0
tcp/443 tcp/80
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
The following Gitlab instance is publicly accessible and looks out-dated :
It is critical to update to a safe version as soon as possible to avoid account takeover.
Severity is mitigated by the need of a valid email address.
Reference:
Severity: high
Fingerprint: db64c48d331961cce5776b3a892edddd892edddd892edddd892edddd892edddd
Found vulnerable Gitlab instance Affected by CVE-2023-7028
Open service 82.148.4.126:80
2024-12-22 00:59
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sun, 22 Dec 2024 00:59:41 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNY120KF3ERH9P2TJ8QJ984","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNY120KF3ERH9P2TJ8QJ984 X-Runtime: 0.078233 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-12-22 00:10
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sun, 22 Dec 2024 00:10:15 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFNV6HWZ6967EZTYV1W4D5CB","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFNV6HWZ6967EZTYV1W4D5CB X-Runtime: 0.048851 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:80
2024-12-20 00:34
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 20 Dec 2024 00:34:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGQT0ZYQ86QZ4MRNEX6761H","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGQT0ZYQ86QZ4MRNEX6761H X-Runtime: 0.031237 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-12-19 22:12
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 19 Dec 2024 22:12:37 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFGFNQTZJHPP6VR3G2SVSVJ6","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFGFNQTZJHPP6VR3G2SVSVJ6 X-Runtime: 0.028614 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:80
2024-12-18 01:47
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Wed, 18 Dec 2024 01:47:14 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBQ58MSHGEWRVVCT3DTACV3","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBQ58MSHGEWRVVCT3DTACV3 X-Runtime: 0.029382 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-12-18 00:21
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Wed, 18 Dec 2024 00:21:52 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JFBJ8Z2ZS6623RYGZ14XWJ2S","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JFBJ8Z2ZS6623RYGZ14XWJ2S X-Runtime: 0.032397 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:80
2024-12-15 23:52
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sun, 15 Dec 2024 23:52:50 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF6BTB2P3E4YYGSRBFCRKJTH","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF6BTB2P3E4YYGSRBFCRKJTH X-Runtime: 0.032101 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-12-15 22:19
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sun, 15 Dec 2024 22:19:23 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF66F877TF159KAV9FW0AWA5","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF66F877TF159KAV9FW0AWA5 X-Runtime: 0.024494 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:80
2024-12-14 00:05
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 14 Dec 2024 00:05:40 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF17RDPBNA02Z2Z904QJNK4M","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF17RDPBNA02Z2Z904QJNK4M X-Runtime: 0.023313 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-12-13 21:59
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 13 Dec 2024 21:59:28 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JF10HBDK8ZH11Q06T3FKW6JZ","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JF10HBDK8ZH11Q06T3FKW6JZ X-Runtime: 0.031233 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:80
2024-12-12 01:04
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 12 Dec 2024 01:04:22 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW6AEG424YE2K2VD584GBAT","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW6AEG424YE2K2VD584GBAT X-Runtime: 0.060873 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-12-12 00:39
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 12 Dec 2024 00:39:37 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JEW4X4W62G3GNSNV64XANSSF","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JEW4X4W62G3GNSNV64XANSSF X-Runtime: 0.031572 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:80
2024-12-02 01:08
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Mon, 02 Dec 2024 01:08:54 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2EKJP0XZEB8QD2PY1A94GE","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2EKJP0XZEB8QD2PY1A94GE X-Runtime: 0.024583 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-12-01 23:54
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sun, 01 Dec 2024 23:54:11 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JE2AAR70GSQZ6H5SQ08SAH83","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JE2AAR70GSQZ6H5SQ08SAH83 X-Runtime: 0.022396 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:80
2024-11-30 00:49
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Sat, 30 Nov 2024 00:49:01 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX8NQV66JQR5XX45J4XAA48","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX8NQV66JQR5XX45J4XAA48 X-Runtime: 0.081144 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-11-29 23:46
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Fri, 29 Nov 2024 23:46:43 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDX53N50BPEBK1H1JSDG275D","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDX53N50BPEBK1H1JSDG275D X-Runtime: 0.025885 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:80
2024-11-28 00:33
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Thu, 28 Nov 2024 00:33:46 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: http://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR30BN5RVQ0ZK3GBET1XDA1","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR30BN5RVQ0ZK3GBET1XDA1 X-Runtime: 0.024137 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>
Open service 82.148.4.126:443
2024-11-27 23:43
HTTP/1.1 302 Found Server: nginx/1.18.0 (Ubuntu) Date: Wed, 27 Nov 2024 23:43:32 GMT Content-Type: text/html; charset=utf-8 Content-Length: 101 Location: https://82.148.4.126/users/sign_in Connection: close Cache-Control: no-cache Content-Security-Policy: Permissions-Policy: interest-cohort=() X-Content-Type-Options: nosniff X-Download-Options: noopen X-Frame-Options: SAMEORIGIN X-Gitlab-Meta: {"correlation_id":"01JDR04CD5JA9KX714D0PJ74N8","version":"1"} X-Permitted-Cross-Domain-Policies: none X-Request-Id: 01JDR04CD5JA9KX714D0PJ74N8 X-Runtime: 0.030249 X-Ua-Compatible: IE=edge X-Xss-Protection: 1; mode=block Strict-Transport-Security: max-age=63072000 Referrer-Policy: strict-origin-when-cross-origin <html><body>You are being <a href="https://git.abflow.uz/users/sign_in">redirected</a>.</body></html>