Heroku
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b885ff4386ff9edc86ff9edc86ff9edc86ff9edc86ff9edc
Public Swagger UI/API detected at path: /swagger.json - sample paths: GET /restApi/getInstructorList
Open service 15.197.149.68:443 · member.animationbootcamp.info
2026-01-10 02:31
HTTP/1.1 303 See Other
Content-Length: 0
Date: Sat, 10 Jan 2026 02:31:53 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=n1gMP464y2Fbbln%2BHY70mZ7anmIbHKgq18l3POwEM7k%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1768012313"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=n1gMP464y2Fbbln%2BHY70mZ7anmIbHKgq18l3POwEM7k%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1768012313"
Request-Time: 5
Server: Heroku
Set-Cookie: PLAY_SESSION=; Max-Age=0; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Path=/; Secure; HTTPOnly
Strict-Transport-Security: max-age=31536000; includeSubDomains
Via: 1.1 heroku-router
Connection: close
Open service 15.197.149.68:443 · member.animationbootcamp.info
2026-01-02 23:01
HTTP/1.1 303 See Other
Content-Length: 0
Date: Fri, 02 Jan 2026 23:01:06 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=2TiGW6zLXvgz554xM1Gkcz00fIXF5rFIkjN4iBlRkh0%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1767394866"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=2TiGW6zLXvgz554xM1Gkcz00fIXF5rFIkjN4iBlRkh0%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1767394866"
Request-Time: 3
Server: Heroku
Set-Cookie: PLAY_SESSION=; Max-Age=0; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Path=/; Secure; HTTPOnly
Strict-Transport-Security: max-age=31536000; includeSubDomains
Via: 1.1 heroku-router
Connection: close
Open service 15.197.149.68:443 · member.animationbootcamp.info
2025-12-23 07:56
HTTP/1.1 303 See Other
Content-Length: 0
Date: Tue, 23 Dec 2025 07:56:30 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=uQvPUaltJAeP68DlspBhrfbu%2Fpc9bl4WkFxwigaFgTo%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766476590"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=uQvPUaltJAeP68DlspBhrfbu%2Fpc9bl4WkFxwigaFgTo%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766476590"
Request-Time: 4
Server: Heroku
Set-Cookie: PLAY_SESSION=; Max-Age=0; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Path=/; Secure; HTTPOnly
Strict-Transport-Security: max-age=31536000; includeSubDomains
Via: 1.1 heroku-router
Connection: close
Open service 15.197.149.68:443 · member.animationbootcamp.info
2025-12-20 21:09
HTTP/1.1 303 See Other
Content-Length: 0
Date: Sat, 20 Dec 2025 21:09:34 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=vdCM9LWyVCOc2hVl%2BMjFiXSWzdCGFd1IKTtyqdFAPt4%3D\u0026sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6\u0026ts=1766264974"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=vdCM9LWyVCOc2hVl%2BMjFiXSWzdCGFd1IKTtyqdFAPt4%3D&sid=929419e7-33ea-4e2f-85f0-7d8b7cd5cbd6&ts=1766264974"
Request-Time: 4
Server: Heroku
Set-Cookie: PLAY_SESSION=; Max-Age=0; Expires=Thu, 01 Jan 1970 00:00:00 GMT; Path=/; Secure; HTTPOnly
Strict-Transport-Security: max-age=31536000; includeSubDomains
Via: 1.1 heroku-router
Connection: close