Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 20.50.2.34:443 · api.dev.idas-cloudservices.net
2026-01-10 02:14
HTTP/1.1 200 OK Content-Length: 175 Connection: close Content-Type: text/html; charset=utf-8 Date: Sat, 10 Jan 2026 02:15:25 GMT Server: Kestrel Access-Control-Expose-Headers: Request-Context Cache-Control: private Set-Cookie: ARRAffinity=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;Secure;Domain=api.dev.idas-cloudservices.net Set-Cookie: ARRAffinitySameSite=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.dev.idas-cloudservices.net Request-Context: appId=cid-v1:7e1b68e1-53e1-4eca-991d-9f752854601d Request-Context: appId=cid-v1:1c0646b2-8f3d-442d-8d12-63f7f5f32bca X-AspNetMvc-Version: 5.3 X-Powered-By: ASP.NET <html><head><meta http-equiv="refresh" content="3;url=/swagger"></head>You will be redirected to Swagger after 3 seconds. <a href="/swagger">Go to Swagger</a> right now</html>
Open service 20.50.2.34:443 · api.dev.idas-cloudservices.net
2026-01-02 23:39
HTTP/1.1 200 OK Content-Length: 175 Connection: close Content-Type: text/html; charset=utf-8 Date: Fri, 02 Jan 2026 23:39:59 GMT Server: Kestrel Access-Control-Expose-Headers: Request-Context Cache-Control: private Set-Cookie: ARRAffinity=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;Secure;Domain=api.dev.idas-cloudservices.net Set-Cookie: ARRAffinitySameSite=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.dev.idas-cloudservices.net Request-Context: appId=cid-v1:7e1b68e1-53e1-4eca-991d-9f752854601d Request-Context: appId=cid-v1:1c0646b2-8f3d-442d-8d12-63f7f5f32bca X-AspNetMvc-Version: 5.3 X-Powered-By: ASP.NET <html><head><meta http-equiv="refresh" content="3;url=/swagger"></head>You will be redirected to Swagger after 3 seconds. <a href="/swagger">Go to Swagger</a> right now</html>
Open service 20.50.2.34:443 · api.dev.idas-cloudservices.net
2025-12-23 10:02
HTTP/1.1 200 OK Content-Length: 175 Connection: close Content-Type: text/html; charset=utf-8 Date: Tue, 23 Dec 2025 10:02:41 GMT Server: Kestrel Access-Control-Expose-Headers: Request-Context Cache-Control: private Set-Cookie: ARRAffinity=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;Secure;Domain=api.dev.idas-cloudservices.net Set-Cookie: ARRAffinitySameSite=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.dev.idas-cloudservices.net Request-Context: appId=cid-v1:7e1b68e1-53e1-4eca-991d-9f752854601d Request-Context: appId=cid-v1:1c0646b2-8f3d-442d-8d12-63f7f5f32bca X-AspNetMvc-Version: 5.3 X-Powered-By: ASP.NET <html><head><meta http-equiv="refresh" content="3;url=/swagger"></head>You will be redirected to Swagger after 3 seconds. <a href="/swagger">Go to Swagger</a> right now</html>
Open service 20.50.2.34:443 · api.dev.idas-cloudservices.net
2025-12-21 12:57
HTTP/1.1 200 OK Content-Length: 175 Connection: close Content-Type: text/html; charset=utf-8 Date: Sun, 21 Dec 2025 12:57:34 GMT Server: Kestrel Access-Control-Expose-Headers: Request-Context Cache-Control: private Set-Cookie: ARRAffinity=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;Secure;Domain=api.dev.idas-cloudservices.net Set-Cookie: ARRAffinitySameSite=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.dev.idas-cloudservices.net Request-Context: appId=cid-v1:7e1b68e1-53e1-4eca-991d-9f752854601d Request-Context: appId=cid-v1:1c0646b2-8f3d-442d-8d12-63f7f5f32bca X-AspNetMvc-Version: 5.3 X-Powered-By: ASP.NET <html><head><meta http-equiv="refresh" content="3;url=/swagger"></head>You will be redirected to Swagger after 3 seconds. <a href="/swagger">Go to Swagger</a> right now</html>
Open service 20.50.2.34:80 · api.dev.idas-cloudservices.net
2025-12-21 12:57
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sun, 21 Dec 2025 12:57:34 GMT Location: https://api.dev.idas-cloudservices.net/
Open service 20.50.2.34:443 · api.dev.idas-cloudservices.net
2025-12-20 16:22
HTTP/1.1 200 OK Content-Length: 175 Connection: close Content-Type: text/html; charset=utf-8 Date: Sat, 20 Dec 2025 16:22:05 GMT Server: Kestrel Access-Control-Expose-Headers: Request-Context Cache-Control: private Set-Cookie: ARRAffinity=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;Secure;Domain=api.dev.idas-cloudservices.net Set-Cookie: ARRAffinitySameSite=cb397420c2f804f498c300d8ac6863c3e812e17ad542e0813210be5d26d9851f;Path=/;HttpOnly;SameSite=None;Secure;Domain=api.dev.idas-cloudservices.net Request-Context: appId=cid-v1:7e1b68e1-53e1-4eca-991d-9f752854601d Request-Context: appId=cid-v1:1c0646b2-8f3d-442d-8d12-63f7f5f32bca X-AspNetMvc-Version: 5.3 X-Powered-By: ASP.NET <html><head><meta http-equiv="refresh" content="3;url=/swagger"></head>You will be redirected to Swagger after 3 seconds. <a href="/swagger">Go to Swagger</a> right now</html>