Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad0354928600c357b65b87d9ad6135a18581059011bd71c
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Ansatt/GetAktiveAnsatteByButikkID/{butikkId}
GET /api/Ansatt/SearchUserInAdminSystem
GET /api/Bruker
GET /api/Butikk/GetAktiveButikkerForCurrentUser
GET /api/Butikk/{butikkId}
GET /api/Dokument/{id}
GET /api/Ingrediens/{gtin}/gln/{gln}
GET /api/Ingrediens/{gtin}/gln/{gln}/image
GET /api/ProdusertResept/{produsertReseptId}
GET /api/Resept/export
GET /api/Resept/useroptions
GET /api/Resept/{epdNr}
GET /api/Resept/{reseptId}/reseptTypeKode/{reseptTypeKode}
GET /api/Resept/{reseptId}/reseptTypeKode/{reseptTypeKode}/dokument/{dokumentId}
GET /api/ReseptMottaker
POST /api/Ansatt
POST /api/Ansatt/Activate/{objectId}
POST /api/Ansatt/DeActivate/{objectId}
POST /api/Ansatt/search
POST /api/Butikk/Activate/{butikkId}
POST /api/Butikk/DeActivate/{butikkId}
POST /api/Butikk/search
POST /api/Butikk/searchNewButikker
POST /api/Butikk/{loepeNr}
POST /api/ButikkAnsatt/{ansattId}/{butikkId}
POST /api/Dokument
POST /api/EventReceiver/reseed
POST /api/EventReceiver/{code}
POST /api/Ingrediens/import
POST /api/Ingrediens/reindex
POST /api/Ingrediens/search
POST /api/Plu/import
POST /api/Plu/override/{reseptId}/{pluCode}
POST /api/Plu/search
POST /api/ProdusertResept
POST /api/ProdusertResept/search
POST /api/Resept/avvis
POST /api/Resept/deactivate
POST /api/Resept/dokument
POST /api/Resept/getorclone
POST /api/Resept/godkjenn
POST /api/Resept/import
POST /api/Resept/kladd
POST /api/Resept/qa
POST /api/Resept/reindex
POST /api/Resept/reindexone/{reseptId}
POST /api/Resept/search
POST /api/Resept/slett
POST /codeValues
POST /companies
POST /units
Open service 20.50.2.68:443 · epdbedriftapi-test.tradesolution.no
2026-01-23 13:08
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Fri, 23 Jan 2026 13:09:03 GMT Server: Kestrel Location: /swagger Request-Context: appId=cid-v1:bfbc791a-8da4-49c8-8f83-a81335b84426
Open service 20.50.2.68:443 · epdbedriftapi-test.tradesolution.no
2026-01-11 01:16
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Sun, 11 Jan 2026 01:17:36 GMT Server: Kestrel Location: /swagger Request-Context: appId=cid-v1:bfbc791a-8da4-49c8-8f83-a81335b84426
Open service 20.50.2.68:80 · epdbedriftapi-test.tradesolution.no
2026-01-11 01:16
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sun, 11 Jan 2026 01:17:35 GMT Location: https://epdbedriftapi-test.tradesolution.no/