hide
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d603c0f71de7cb63fbe940d4ed46ae9a95f8c00575a
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /deployment
GET /deployment/Deployment-Logs
GET /users-management/get-all-user-group
GET /users-management/get-all-users
GET /users-management/get-by-id/{id}
GET /users-management/get-by-username/{userName}
GET /users-management/get-group-fascias
GET /users-management/get-groups-count
GET /users-management/get-user-api-access-types
GET /users-management/get-user-permissions
GET /users-management/get-user-rights
GET /users-management/get-user-statuses
GET /users-management/get-user-types
GET /users-management/get-users-count
GET /users-management/sync-all-users
GET /users-management/user-management-logs
POST /deployment/settings
POST /users-management/add-group
POST /users-management/add-user
POST /users-management/clone-user
POST /users-management/disable-user
POST /users-management/disable-user-group
POST /users-management/enable-user
POST /users-management/enable-user-group
POST /users-management/remove-all-users-token
POST /users-management/update-user
POST /users-management/update-user-group
POST /users/authenticate
POST /users/refresh-token
POST /users/revoke-refresh-token
POST /users/revoke-token
POST /users/update-password
Open service 151.101.1.91:443 · api-staging.prism.jdplc.com
2026-01-09 05:12
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 location: index.html x-content-type-options: nosniff strict-transport-security: max-age=15724800; includeSubDomains x-xss-protection: 1 server: hide x-frame-options: DENY Accept-Ranges: bytes Date: Fri, 09 Jan 2026 05:12:12 GMT Via: 1.1 varnish X-Served-By: cache-lga21938-LGA, cache-lga21936-LGA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1767935532.213554,VS0,VE328 Vary: Accept-Encoding Cache-Control: private, no-store
Open service 151.101.1.91:443 · api-staging.prism.jdplc.com
2026-01-02 12:00
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 x-content-type-options: nosniff x-xss-protection: 1 strict-transport-security: max-age=15724800; includeSubDomains x-frame-options: DENY location: index.html server: hide Accept-Ranges: bytes Date: Fri, 02 Jan 2026 12:00:31 GMT Via: 1.1 varnish X-Served-By: cache-sin-wsat1880032-SIN, cache-sin-wsat1880032-SIN X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1767355231.859374,VS0,VE851 Vary: Accept-Encoding Cache-Control: private, no-store
Open service 151.101.1.91:443 · api-staging.prism.jdplc.com
2025-12-30 13:38
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 x-content-type-options: nosniff x-xss-protection: 1 strict-transport-security: max-age=15724800; includeSubDomains x-frame-options: DENY location: index.html server: hide Accept-Ranges: bytes Date: Tue, 30 Dec 2025 13:38:34 GMT Via: 1.1 varnish X-Served-By: cache-fra-eddf8230078-FRA, cache-fra-eddf8230160-FRA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1767101914.319467,VS0,VE222 Vary: Accept-Encoding Cache-Control: private, no-store
Open service 151.101.1.91:443 · api-staging.prism.jdplc.com
2025-12-22 13:02
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 x-xss-protection: 1 strict-transport-security: max-age=15724800; includeSubDomains server: hide x-content-type-options: nosniff location: index.html x-frame-options: DENY Accept-Ranges: bytes Date: Mon, 22 Dec 2025 13:02:24 GMT Via: 1.1 varnish X-Served-By: cache-fra-eddf8230046-FRA, cache-fra-eddf8230135-FRA X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766408544.107445,VS0,VE172 Vary: Accept-Encoding Cache-Control: private, no-store
Open service 151.101.1.91:443 · api-staging.prism.jdplc.com
2025-12-20 09:27
HTTP/1.1 301 Moved Permanently Connection: close Content-Length: 0 x-content-type-options: nosniff x-xss-protection: 1 strict-transport-security: max-age=15724800; includeSubDomains x-frame-options: DENY location: index.html server: hide Accept-Ranges: bytes Date: Sat, 20 Dec 2025 09:27:27 GMT Via: 1.1 varnish X-Served-By: cache-sin-wsss1830065-SIN, cache-sin-wsss1830027-SIN X-Cache: MISS, MISS X-Cache-Hits: 0, 0 X-Timer: S1766222847.885861,VS0,VE746 Vary: Accept-Encoding Cache-Control: private, no-store