cloudflare
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
Open service 207.189.149.20:443 · multimedia.unicredit.eu
2026-01-09 11:30
HTTP/1.1 302 Found
Date: Fri, 09 Jan 2026 11:30:56 GMT
Content-Length: 0
Connection: close
CF-RAY: 9bb39afc08ad8e2c-FRA
strict-transport-security: max-age=31536000; includeSubDomains
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
referrer-policy: strict-origin-when-cross-origin
content_security_policy: script-src 'self' 'unsafe-eval' 'unsafe-inline' *.zoom.us zoom.us *.kollective.app *.qumucloud.com *.googletagmanager.com *.google-analytics.com *.newrelic.com; child-src 'self' blob: screen-recorder-launcher-jre14: *.qumucloud.com wss://*.zoom.us; frame-ancestors http: https:; object-src 'none'; form-action 'self' *.oktapreview.com *.onmicrosoft.com; base-uri 'self'; report-uri https://analytics.qumucloud.com/log;
Set-Cookie: KV_CLIENT_SESSION_ID=uaDsM8dRrwZtdk46gzH84t:J9v67IDZO6loYhqk1CPyxaG9YDWXFJOeuf2zkgyKU5E=; Max-Age=31536000; Expires=Sat, 09-Jan-2027 11:30:56 GMT; Path=/; Secure; HttpOnly; SameSite=None
Set-Cookie: JSESSIONID=22AC93BC7D14CB463B00DE14CFD5D3E6; Max-Age=1209600; Expires=Fri, 23-Jan-2026 11:30:56 GMT; Path=/; Secure; HttpOnly; SameSite=None
Set-Cookie: i18next=en-GB; Max-Age=31536000; Expires=Sat, 09-Jan-2027 11:30:56 GMT; Path=/; Secure; SameSite=None
Set-Cookie: _cfuvid=gfeoVjgnfDxdnHS35VUSxbvcxZ21f6gCBg8aj1MJNUc-1767958256043-0.0.1.1-604800000; path=/; domain=.multimedia.unicredit.eu; HttpOnly; Secure; SameSite=None
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
pragma: no-cache
expires: 0
location: https://multimedia.unicredit.eu/portal
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=diPHe4c%2BdZQnmxliAQlM8fQ62mshZmC5Rg1nrWg2IzSFA3VhhnQflVz4095Rva5p3oY%2Fcs9yKNaA3vrc4DlYhk9iPJ2rxRB9hUpX%2FJPhb67%2FEEZHl7PfvAb0FsS8Ogif%2BxaoftaWEm2z"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 207.189.149.20:443 · multimedia.unicredit.eu
2026-01-02 03:11
HTTP/1.1 302 Found
Date: Fri, 02 Jan 2026 03:11:52 GMT
Content-Length: 0
Connection: close
CF-RAY: 9b77124f78e18c46-FRA
strict-transport-security: max-age=31536000; includeSubDomains
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
referrer-policy: strict-origin-when-cross-origin
content_security_policy: script-src 'self' 'unsafe-eval' 'unsafe-inline' *.zoom.us zoom.us *.kollective.app *.qumucloud.com *.googletagmanager.com *.google-analytics.com *.newrelic.com; child-src 'self' blob: screen-recorder-launcher-jre14: *.qumucloud.com wss://*.zoom.us; frame-ancestors http: https:; object-src 'none'; form-action 'self' *.oktapreview.com *.onmicrosoft.com; base-uri 'self'; report-uri https://analytics.qumucloud.com/log;
Set-Cookie: KV_CLIENT_SESSION_ID=4KulsGxPK9sYk9pPhsppde:OCA8EHvVkY8Fyk3vyFOIkJuSlzQw/AXp5uemJFrqKZ8=; Max-Age=31536000; Expires=Sat, 02-Jan-2027 03:11:52 GMT; Path=/; Secure; HttpOnly; SameSite=None
Set-Cookie: JSESSIONID=0CB2DA769DEB62BA38747B90A47EEA15; Max-Age=1209600; Expires=Fri, 16-Jan-2026 03:11:52 GMT; Path=/; Secure; HttpOnly; SameSite=None
Set-Cookie: i18next=en-GB; Max-Age=31536000; Expires=Sat, 02-Jan-2027 03:11:52 GMT; Path=/; Secure; SameSite=None
Set-Cookie: _cfuvid=OZzsBcw2BtFdARacJteyHiYoyjKj1Eyq4zUfIEA1BqY-1767323512304-0.0.1.1-604800000; path=/; domain=.multimedia.unicredit.eu; HttpOnly; Secure; SameSite=None
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
pragma: no-cache
expires: 0
location: https://multimedia.unicredit.eu/portal
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=%2FH7vWi5MrzH3Jv6FuGaRPl35tU8CwuIM%2F3pdZt6U26RTSdIKL7HhHN8eKECKhsr0LkIbkIZuUB0T2fyOwJ6iucEMZbqAMfKgkma0Y69%2F5Ct0lJ9C5aK4CJNUQE9awIbGxzYZRbBjRCLr"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare
Open service 207.189.149.20:443 · multimedia.unicredit.eu
2025-12-22 06:16
HTTP/1.1 302 Found
Date: Mon, 22 Dec 2025 06:16:33 GMT
Content-Length: 0
Connection: close
CF-RAY: 9b1d7db7fc8527f6-EWR
strict-transport-security: max-age=31536000; includeSubDomains
x-xss-protection: 1; mode=block
x-content-type-options: nosniff
referrer-policy: strict-origin-when-cross-origin
content_security_policy: script-src 'self' 'unsafe-eval' 'unsafe-inline' *.zoom.us zoom.us *.kollective.app *.qumucloud.com *.googletagmanager.com *.google-analytics.com *.newrelic.com; child-src 'self' blob: screen-recorder-launcher-jre14: *.qumucloud.com wss://*.zoom.us; frame-ancestors http: https:; object-src 'none'; form-action 'self' *.oktapreview.com *.onmicrosoft.com; base-uri 'self'; report-uri https://analytics.qumucloud.com/log;
Set-Cookie: KV_CLIENT_SESSION_ID=LNR64dRIOZcozlBjMTdrU0:liWaoRtnhgRdf4mgggYbpvpr0uGp/70lKdkCjfVrgVI=; Max-Age=31536000; Expires=Tue, 22-Dec-2026 06:16:33 GMT; Path=/; Secure; HttpOnly; SameSite=None
Set-Cookie: JSESSIONID=66ADDD51DBE0A9F442F2C8C07A74A0B0; Max-Age=1209600; Expires=Mon, 05-Jan-2026 06:16:33 GMT; Path=/; Secure; HttpOnly; SameSite=None
Set-Cookie: i18next=en-GB; Max-Age=31536000; Expires=Tue, 22-Dec-2026 06:16:33 GMT; Path=/; Secure; SameSite=None
Set-Cookie: _cfuvid=V8Eb8nsWbAxeKZEb3wNn32sa1lMGGcpiCY6aeddJJgw-1766384193381-0.0.1.1-604800000; path=/; domain=.multimedia.unicredit.eu; HttpOnly; Secure; SameSite=None
Cache-Control: no-cache, no-store, max-age=0, must-revalidate
pragma: no-cache
expires: 0
location: https://multimedia.unicredit.eu/portal
via: 1.1 google
alt-svc: h3=":443"; ma=86400
cf-cache-status: DYNAMIC
Report-To: {"endpoints":[{"url":"https:\/\/a.nel.cloudflare.com\/report\/v4?s=c0GnaLhYSsfNHTL1KAcdSD4cQOCNzkwuoI05SV2RFbyhSjgmEs%2FhPlXmOF7eZ88qP9Qh83%2F74nGTrG43h9fxSb5wuBMmZox2Sd%2F0QC1XOAa60k5DyfMOPld9dwwjMIWNw0Kl22IkZ8iv"}],"group":"cf-nel","max_age":604800}
NEL: {"success_fraction":0,"report_to":"cf-nel","max_age":604800}
Server: cloudflare