Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 20.50.2.50:443 · dev.app.solaflex.com
2026-01-23 13:56
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Fri, 23 Jan 2026 13:57:30 GMT Server: Kestrel Location: /index.html Strict-Transport-Security: max-age=2592000 Content-Security-Policy: frame-ancestors 'self' https://shop.ceraflex.at https://ceraflex.stag.interad.at https://ceraflex.test.interad.at X-Correlation-Id: cc7d9f624bf94a3c9c4053076f06cc90
Open service 20.50.2.50:80 · dev.app.solaflex.com
2026-01-10 12:17
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sat, 10 Jan 2026 12:18:41 GMT Location: https://dev.app.solaflex.com/
Open service 20.50.2.50:443 · dev.app.solaflex.com
2026-01-10 12:17
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Sat, 10 Jan 2026 12:18:42 GMT Server: Kestrel Location: /index.html Strict-Transport-Security: max-age=2592000 Content-Security-Policy: frame-ancestors 'self' https://shop.ceraflex.at https://ceraflex.stag.interad.at https://ceraflex.test.interad.at X-Correlation-Id: 86603ec20fa541e7b5defe5b10358bdb