BunnyCDN-DE1-1330
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4308e82594d30f4d1e5e32a2d40f67077e327cf702
Public Swagger UI/API detected at path: /swagger.json - sample paths:
DELETE /api/v1/mailList/{orgKey}/{unsubscribeKey}
GET /api/v1/adminAccount/current
GET /api/v1/authStatus
GET /api/v1/claim/{uuid}
GET /api/v1/claimFile/{uuid}/publicUrl
GET /api/v1/crud/action
GET /api/v1/crud/action/{id}
GET /api/v1/crud/adminAccount
GET /api/v1/crud/adminAccount/{id}
GET /api/v1/crud/adminAccountRole
GET /api/v1/crud/adminAccountRole/{id}
GET /api/v1/crud/adminSessionToken
GET /api/v1/crud/adminSessionToken/{id}
GET /api/v1/crud/authenticityReport
GET /api/v1/crud/authenticityReport/{id}
GET /api/v1/crud/claim
GET /api/v1/crud/claim/{id}
GET /api/v1/crud/claimEventLogEntry
GET /api/v1/crud/claimEventLogEntry/{id}
GET /api/v1/crud/claimFile
GET /api/v1/crud/claimFile/{id}
GET /api/v1/crud/deletedRecord
GET /api/v1/crud/deletedRecord/{id}
GET /api/v1/crud/loginLinkToken
GET /api/v1/crud/loginLinkToken/{id}
GET /api/v1/crud/mailListParticipant
GET /api/v1/crud/mailListParticipant/{id}
GET /api/v1/crud/mailTemplate
GET /api/v1/crud/mailTemplate/{id}
GET /api/v1/crud/organisation
GET /api/v1/crud/organisation/{id}
GET /api/v1/crud/scheduledHook
GET /api/v1/crud/scheduledHook/{id}
GET /api/v1/crud/sessionToken
GET /api/v1/crud/sessionToken/{id}
GET /api/v1/crud/state
GET /api/v1/crud/state/{id}
GET /api/v1/crud/submitToken
GET /api/v1/crud/submitToken/{id}
GET /api/v1/crud/uniquenessReport
GET /api/v1/crud/uniquenessReport/{id}
GET /api/v1/crud/uploadedFile
GET /api/v1/crud/uploadedFile/{id}
GET /api/v1/crud/user
GET /api/v1/crud/user/{id}
GET /api/v1/crud/userEventLogEntry
GET /api/v1/crud/userEventLogEntry/{id}
GET /api/v1/kvk/search
GET /api/v1/status
GET /api/v1/user/current
GET /api/v1/user/emailPreferences
GET /api/v1/user/login/getAuthenticationMethods
GET /api/v1/zipcodeCheck
POST /api/v1/adminAccount/login
POST /api/v1/adminAccount/logout
POST /api/v1/claim
POST /api/v1/claim/{id}/retract
POST /api/v1/claim/{uuid}/getUploadUrl
POST /api/v1/claim/{uuid}/registerUser
POST /api/v1/mailList/{orgKey}/participant
POST /api/v1/user/current/logout
POST /api/v1/user/current/sendConfirmEmailMail
POST /api/v1/user/current/setPassword
POST /api/v1/user/current/setSkippedSettingPassword
POST /api/v1/user/login/sendMagicLoginLink
POST /api/v1/user/login/sendResetPasswordLink
POST /api/v1/user/login/withLoginToken
POST /api/v1/user/login/withPassword
POST /api/v1/user/{userId}/loginAs
PUT /api/v1/adminAccount/password
Open service 185.111.111.156:443 · lj2.staging.massaschadeconsument.nl
2026-01-09 15:54
HTTP/1.1 404 Not Found
Date: Fri, 09 Jan 2026 15:55:00 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 60
Connection: close
Server: BunnyCDN-DE1-1330
CDN-PullZone: 714448
CDN-RequestCountryCode: GB
Cache-Control: public, max-age=0
CDN-ProxyVer: 1.43
CDN-RequestPullSuccess: True
CDN-RequestPullCode: 404
CDN-CachedAt: 01/09/2026 15:55:00
CDN-EdgeStorageId: 1330
CDN-RequestId: f639458a3f35b5132be3513c12c4cf30
CDN-Cache: BYPASS
CDN-Status: 404
CDN-RequestTime: 0
{"statusCode":404,"error":"Not Found","message":"Not Found"}
Open service 185.111.111.156:443 · lj2.staging.massaschadeconsument.nl
2025-12-22 22:37
HTTP/1.1 404 Not Found
Date: Mon, 22 Dec 2025 22:37:33 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 60
Connection: close
Server: BunnyCDN-DE1-1330
CDN-PullZone: 714448
CDN-RequestCountryCode: CA
Cache-Control: public, max-age=0
CDN-ProxyVer: 1.41
CDN-RequestPullSuccess: True
CDN-RequestPullCode: 404
CDN-CachedAt: 12/22/2025 22:37:33
CDN-EdgeStorageId: 1330
CDN-RequestId: 9a704dce609c0c2e8632941d50898fdc
CDN-Cache: BYPASS
CDN-Status: 404
CDN-RequestTime: 0
{"statusCode":404,"error":"Not Found","message":"Not Found"}
Open service 185.111.111.156:443 · lj2.staging.massaschadeconsument.nl
2025-12-21 04:45
HTTP/1.1 404 Not Found
Date: Sun, 21 Dec 2025 04:45:43 GMT
Content-Type: application/json; charset=utf-8
Content-Length: 60
Connection: close
Server: BunnyCDN-DE1-1330
CDN-PullZone: 714448
CDN-RequestCountryCode: DE
Cache-Control: public, max-age=0
CDN-ProxyVer: 1.41
CDN-RequestPullSuccess: True
CDN-RequestPullCode: 404
CDN-CachedAt: 12/21/2025 04:45:43
CDN-EdgeStorageId: 1330
CDN-RequestId: 0483ed6f29f3520fcec2904beec59c53
CDN-Cache: BYPASS
CDN-Status: 404
CDN-RequestTime: 0
{"statusCode":404,"error":"Not Found","message":"Not Found"}