Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d6024f00ab8edabf7f2fb3d66ce6bbca63bf8272c9d
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /IdentificationDocumentSubType
GET /IdentificationDocumentSubType/{id}
GET /IdentificationDocumentType/{id}
GET /LawSchool/{id}
GET /LegalIssues/All
GET /LegalIssues/Search
GET /LegalIssues/{id}
GET /LegalIssues/{id}/Childs
GET /LegalStates/All
GET /LegalStates/Search
GET /LegalStates/{id}
GET /LegalStates/{id}/Childs
GET /LextoolsBi/GetAzureToken
GET /PartTypes/All
GET /PersonCategory/code/{code}
GET /PersonCategory/{id}
GET /PersonType/{id}
GET /SendGridTemplate/{id}
GET /UserRoles/Security
GET /additionalContactDataType/{id}
GET /additionalContactDetail/{id}
GET /address/{id}
GET /addressType/{id}
GET /auth/RenewToken
GET /companies/{id}
GET /contactPerson/{id}
GET /country/{id}
GET /health
GET /persons/{id}
GET /personsIdentificationDocument/{id}
GET /tenant/ModernInvoice
GET /tenant/{externalId}
GET /tenant/{externalId}/GetLextoolsBiClientToken
GET /tenant/{id}
GET /tenant/{id}/HiredComponents
GET /typeOfRoad/{id}
GET /user
GET /user/GetPermalinkPowerBi/{login}
GET /user/{email}
GET /user/{id}
POST /Burofax/Search
POST /CourtRecords/Search
POST /LTCloudAuth
POST /LextoolsBi/CreateClientToken
POST /Parties/Search
POST /SendGridTemplate
POST /SendGridTemplate/SendWelcomeMessage
POST /States/Search
POST /additionalContactDetail
POST /address
POST /auth/log-in
POST /auth/loginByProduct
POST /auth/sign-up
POST /companies
POST /contactPerson
POST /persons
POST /personsIdentificationDocument
POST /tenant
POST /tenant/{externalId}/ImportUsersFromLegacyDatabase
POST /user/RestartPasswordByEmail
POST /user/RestartPasswordByLogin
POST /user/{ExternalId}
Open service 20.50.64.5:80 · api.ltcloud.lextools.com
2026-01-12 02:55
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 12 Jan 2026 02:56:03 GMT Location: https://api.ltcloud.lextools.com/
Open service 20.50.64.5:443 · api.ltcloud.lextools.com
2026-01-12 02:55
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 12 Jan 2026 02:56:04 GMT Server: Kestrel Location: index.html
Open service 20.50.64.5:443 · api.ltcloud.lextools.com
2026-01-08 20:31
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Thu, 08 Jan 2026 20:32:25 GMT Server: Kestrel Location: index.html
Open service 20.50.64.5:80 · api.ltcloud.lextools.com
2026-01-04 03:17
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sun, 04 Jan 2026 03:17:34 GMT Location: https://api.ltcloud.lextools.com/
Open service 20.50.64.5:443 · api.ltcloud.lextools.com
2026-01-04 03:17
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sun, 04 Jan 2026 03:17:33 GMT Server: Kestrel Location: index.html