Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035490d93fe6452bb4df83eca8c3659f22c89a6daf543
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /admin/v1/sync/workspaces/{workspaceId}/members/{memberId}
DELETE /api/v1/workspaces/{workspaceId}/assignments/{userId}
DELETE /api/v1/workspaces/{workspaceId}/plants/{plantId}
DELETE /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/irrevocably
DELETE /api/v1/workspaces/{workspaceId}/plants/{plantId}/irrevocably
DELETE /api/v1/workspaces/{workspaceId}/vehicles/{vehicleId}
DELETE /api/v1/workspaces/{workspaceId}/vehicles/{vehicleId}/irrevocably
GET /api/v1/apiKeys
GET /api/v1/apiKeys/{apiKeyId}
GET /api/v1/articleInfos
GET /api/v1/cookietext
GET /api/v1/countries
GET /api/v1/disclaimers/{phoneNumber}/{hash}
GET /api/v1/httpsubscriptions
GET /api/v1/httpsubscriptions/{httpSubscriptionId}
GET /api/v1/imprint
GET /api/v1/invitations
GET /api/v1/invitations/{invitationId}
GET /api/v1/locationsearchresults
GET /api/v1/logistic/{phoneNumber}
GET /api/v1/logistic/{phoneNumber}/onboardingstatus
GET /api/v1/my/workspaces
GET /api/v1/myWorkspaceInquiries
GET /api/v1/plantTypes
GET /api/v1/plants
GET /api/v1/plants/{plantId}
GET /api/v1/plants/{plantId}/logo
GET /api/v1/plants/{plantId}/picture
GET /api/v1/sponsors
GET /api/v1/truckBuddyAppInstances/registered
GET /api/v1/truckBuddyAppInstances/registeredPhoneNumber/{phoneNumber}
GET /api/v1/truckBuddyAppInstances/{truckBuddyAppInstanceIdentifier}
GET /api/v1/units
GET /api/v1/units/currencies
GET /api/v1/units/temperatures
GET /api/v1/units/unitTypes
GET /api/v1/units/unitTypes/{unitTypeId}
GET /api/v1/units/{unitId}
GET /api/v1/usergroups/{userGroupId}
GET /api/v1/users/{userId}
GET /api/v1/users/{userId}/profile
GET /api/v1/validations/plant/identifier/{identifierValue}
GET /api/v1/validations/plant/{plantId}/article/identifier/{identifierValue}
GET /api/v1/validations/user/email/{emailValue}
GET /api/v1/validations/workspace/identifier/{identifierValue}
GET /api/v1/vehicles/{vehicleRegistrationNumber}
GET /api/v1/vehicles/{vehicleRegistrationNumber}/presence
GET /api/v1/workspaceInquiries
GET /api/v1/workspaceInquiries/{workspaceInquiryId}
GET /api/v1/workspaceInquiries/{workspaceInquiryId}/features
GET /api/v1/workspaceInquiries/{workspaceInquiryId}/settings
GET /api/v1/workspaceInquiries/{workspaceInquiryId}/workspace
GET /api/v1/workspaces
GET /api/v1/workspaces/settings/workspaceTypes
GET /api/v1/workspaces/{workspaceId}
GET /api/v1/workspaces/{workspaceId}/activeInvitations
GET /api/v1/workspaces/{workspaceId}/apiKeys
GET /api/v1/workspaces/{workspaceId}/apiKeys/{apiKeyId}
GET /api/v1/workspaces/{workspaceId}/companylogo
GET /api/v1/workspaces/{workspaceId}/copyright
GET /api/v1/workspaces/{workspaceId}/emissionsclasses
GET /api/v1/workspaces/{workspaceId}/features
GET /api/v1/workspaces/{workspaceId}/invitations
GET /api/v1/workspaces/{workspaceId}/invitations/{invitationId}
GET /api/v1/workspaces/{workspaceId}/plants
GET /api/v1/workspaces/{workspaceId}/plants/deleted
GET /api/v1/workspaces/{workspaceId}/plants/images/{name}
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/deleted
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/groups
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/additionaldocuments
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/additionaldocuments/{additionalDocumentId}/document
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/appraisal/document
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/epd/document
GET /api/v1/workspaces/{workspaceId}/plants/{plantId}/info
GET /api/v1/workspaces/{workspaceId}/privacy
GET /api/v1/workspaces/{workspaceId}/settings
GET /api/v1/workspaces/{workspaceId}/state
GET /api/v1/workspaces/{workspaceId}/termsofuse
GET /api/v1/workspaces/{workspaceId}/userGroups
GET /api/v1/workspaces/{workspaceId}/users
GET /api/v1/workspaces/{workspaceId}/vehicleTypes
GET /api/v1/workspaces/{workspaceId}/vehicles
GET /api/v1/workspaces/{workspaceId}/vehicles/deleted
GET /api/v1/workspaces/{workspaceId}/vehicles/{id}
GET /api/v1/workspaces/{workspaceId}/workspacelogo
GET /apiinfos
PATCH /api/v1/truckBuddyAppInstances/{truckBuddyAppInstanceIdentifier}/uninstalled
POST /admin/v1/sync/members
POST /api/localization/backup
POST /api/v1/apiKeys/synchronizeRevoked
POST /api/v1/geoarea/calculatecircle
POST /api/v1/logistic/vehicles/truckBuddyEnabledStatus
POST /api/v1/usergroups
POST /api/v1/workspaceInquiries/managed
POST /api/v1/workspaces/{workspaceId}/emissionsclasses/{id}/disable
POST /api/v1/workspaces/{workspaceId}/plants/images/delete
POST /api/v1/workspaces/{workspaceId}/plants/images/upload
POST /api/v1/workspaces/{workspaceId}/plants/{plantId}/article-excelexport
POST /api/v1/workspaces/{workspaceId}/plants/{plantId}/article-import
POST /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/restore
POST /api/v1/workspaces/{workspaceId}/plants/{plantId}/restore
POST /api/v1/workspaces/{workspaceId}/supportuser-invitation
POST /api/v1/workspaces/{workspaceId}/vehicle-excelexport
POST /api/v1/workspaces/{workspaceId}/vehicle-import
POST /api/v1/workspaces/{workspaceId}/vehicleTypes/{id}/disable
POST /api/v1/workspaces/{workspaceId}/vehicles/check-availability
POST /api/v1/workspaces/{workspaceId}/vehicles/{vehicleId}/restore
PUT /admin/v1/sync/members/{memberId}
PUT /api/v1/disclaimers
PUT /api/v1/httpsubscriptions/{httpSubscriptionId}/state
PUT /api/v1/invitations/{invitationId}/state
PUT /api/v1/logistic/{phoneNumber}/invitation
PUT /api/v1/truckBuddyAppInstances/{truckBuddyAppInstanceIdentifier}/preferences
PUT /api/v1/users/{userId}/profilePicture
PUT /api/v1/workspaceInquiries/{workspaceInquiryId}/state/{workspaceState}
PUT /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/appraisal
PUT /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/epd
PUT /api/v1/workspaces/{workspaceId}/plants/{plantId}/articles/{articleId}/visibility
PUT /api/v1/workspaces/{workspaceId}/state/{newState}
PUT /api/v1/workspaces/{workspaceId}/users/{userId}/groupIds
PUT /api/v1/workspaces/{workspaceId}/users/{userId}/lastseen
PUT /api/v1/workspaces/{workspaceId}/vehicles/{vehicleId}/deliverynotetransfer
PUT /api/v1/workspaces/{workspaceId}/vehicles/{vehicleId}/transfermobilephone
Open service 20.50.2.43:443 · dev-bs.q-directories-dev.com
2026-01-09 17:28
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Fri, 09 Jan 2026 17:29:59 GMT Server: Kestrel Location: /swagger/index.html Set-Cookie: ARRAffinity=cb9a1e85b7f446b91cafd7e190ad73d52dcc97f1375ac71d21702bb4d90c19e0;Path=/;HttpOnly;Secure;Domain=dev-bs.q-directories-dev.com Set-Cookie: ARRAffinitySameSite=cb9a1e85b7f446b91cafd7e190ad73d52dcc97f1375ac71d21702bb4d90c19e0;Path=/;HttpOnly;SameSite=None;Secure;Domain=dev-bs.q-directories-dev.com Request-Context: appId=cid-v1:eb736dad-6aaf-4b2c-a598-e22e0a9c2422
Open service 20.50.2.43:443 · dev-bs.q-directories-dev.com
2026-01-02 09:00
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Fri, 02 Jan 2026 09:00:37 GMT Server: Kestrel Location: /swagger/index.html Set-Cookie: ARRAffinity=b87c19a5269869f70deb7cc0a2ed190e1ca72b9babdcf5dd3634affeed69cbc1;Path=/;HttpOnly;Secure;Domain=dev-bs.q-directories-dev.com Set-Cookie: ARRAffinitySameSite=b87c19a5269869f70deb7cc0a2ed190e1ca72b9babdcf5dd3634affeed69cbc1;Path=/;HttpOnly;SameSite=None;Secure;Domain=dev-bs.q-directories-dev.com Request-Context: appId=cid-v1:eb736dad-6aaf-4b2c-a598-e22e0a9c2422
Open service 20.50.2.43:443 · dev-bs.q-directories-dev.com
2025-12-22 21:25
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 22 Dec 2025 21:25:52 GMT Server: Kestrel Location: /swagger/index.html Set-Cookie: ARRAffinity=e5e65e80b466aaeb05b630ce4e72d24ce88f0da0e85596365c8c224a297b7ac2;Path=/;HttpOnly;Secure;Domain=dev-bs.q-directories-dev.com Set-Cookie: ARRAffinitySameSite=e5e65e80b466aaeb05b630ce4e72d24ce88f0da0e85596365c8c224a297b7ac2;Path=/;HttpOnly;SameSite=None;Secure;Domain=dev-bs.q-directories-dev.com Request-Context: appId=cid-v1:eb736dad-6aaf-4b2c-a598-e22e0a9c2422
Open service 20.50.2.43:443 · dev-bs.q-directories-dev.com
2025-12-19 01:59
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Fri, 19 Dec 2025 01:59:46 GMT Server: Kestrel Location: /swagger/index.html Set-Cookie: ARRAffinity=e5e65e80b466aaeb05b630ce4e72d24ce88f0da0e85596365c8c224a297b7ac2;Path=/;HttpOnly;Secure;Domain=dev-bs.q-directories-dev.com Set-Cookie: ARRAffinitySameSite=e5e65e80b466aaeb05b630ce4e72d24ce88f0da0e85596365c8c224a297b7ac2;Path=/;HttpOnly;SameSite=None;Secure;Domain=dev-bs.q-directories-dev.com Request-Context: appId=cid-v1:eb736dad-6aaf-4b2c-a598-e22e0a9c2422