Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035491c08e9ccc10e95d15a72c966acd05fa00ea8c43f
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
DELETE /api/Bestillinger/fromEpd/{epdNumber}/{tsCustomerId}
DELETE /api/Bestillinger/{id}
DELETE /api/CarbonCopy/{carbonCopyId}
DELETE /api/Customer/log/{logId}
DELETE /api/Fotobestillinger/RemoveBestilling
DELETE /api/GruppeOppdrag/{key}
DELETE /api/Oppdrag/{key}
DELETE /api/OppdragsPreferanser/{id}
DELETE /api/OrionEvents/{key}
DELETE /api/Utsettelser/{key}
GET /api/Bestillinger/{oppdragId}
GET /api/CarbonCopy/GetAll
GET /api/CarbonCopy/GetByTsKunderId
GET /api/Customer/Search
GET /api/Customer/Search/{gln}
GET /api/Customer/all
GET /api/Customer/card/{tsKundeId}
GET /api/Customer/getContactPersons/{tsKundeId}
GET /api/Customer/getServiceGroups
GET /api/Customer/logs/{tsKundeId}/{top}
GET /api/FotoQueue
GET /api/FotoQueue/Count
GET /api/Fotobestillinger
GET /api/FotorobQueue
GET /api/FotorobStasjon/scans
GET /api/GruppeOppdrag
GET /api/GruppeOppdrag/getAll
GET /api/GruppeOppdrag/getById/{identityGuid}
GET /api/Lagerplasser
GET /api/Lanseringsvindu
GET /api/LanseringsvinduRapport/Excel/{lanseringsvinduId}
GET /api/MediaStore/GetImageSets/{gtin}/{gln}
GET /api/MediaStore/getPhotorobJobs
GET /api/MediaStore/{gtin}/image
GET /api/MediaStore/{gtin}/metadata
GET /api/MinimumNumberOfImagesPerProduktType
GET /api/Oppdrag/AsPriorityList
GET /api/Oppdrag/GetAllEpdNumbersWithImageDeadlineDate/{date}
GET /api/Oppdrag/ProduktStatus
GET /api/Oppdrag/ProduktStatus/{orderIdentityGuid}
GET /api/OppdragEvent/getFotoCompleteEvents
GET /api/OppdragEvent/getFotoStartedEvents
GET /api/OppdragEvent/{oppdragId}
GET /api/OppdragsPreferanser
GET /api/OppdragsPreferanser/Count/all
GET /api/OppdragsPreferanser/Excel/all
GET /api/OppdragsPreferanser/{tsKundeId}
GET /api/OrionEvents
GET /api/Pakninger
GET /api/Purringer/GetOppdragByTsKunder/{tsKundeId}
GET /api/Purringer/GetTsKunder
GET /api/Purringer/{tsKundeId}/Sjekkpunktkontaktperson
GET /api/Search/byEpdNumber/{epdNumber}
GET /api/Search/byGtin/{gtin}
GET /api/Search/variants
GET /api/Search/variantsAsExcel
GET /api/SjekkpunktOppdrag
GET /api/Sjekkpunktbestillinger
GET /api/Tilleggsgebyr
GET /api/Tilleggsgebyr/{tsKundeId}
GET /api/User/getOrionUser
GET /api/Utsettelser/{oppdragId}
POST /api/Bestillinger
POST /api/CarbonCopy
POST /api/Customer/log
POST /api/Fotobestillinger/AddBestilling
POST /api/FotorobStasjon/scans/RegisterScan/{scannedGtin}
POST /api/FotorobStasjon/scans/RemoveScanFromPakning/{scanId}
POST /api/Lanseringsvindu/SyncLaunchWindowsFromEpd
POST /api/Oppdrag
POST /api/Oppdrag/AppendComment
POST /api/Oppdrag/Get
POST /api/Oppdrag/GetAsExcel
POST /api/Oppdrag/GetOppdragByEpdNumber/{epdNumber}
POST /api/Oppdrag/ReceivedProducts
POST /api/OppdragEvent/CompleteFoto/{gtin}
POST /api/OppdragEvent/EndreLagerplass/{oppdragId}/{lagerplassId}
POST /api/OppdragEvent/StartFoto/{gtin}
POST /api/OrionImport/AddBestillinger/{bestillerId}
POST /api/Purringer/SendPaaminnelser
POST /api/Purringer/SendPurringer
POST /api/SjekkpunktOppdrag/AddUtsettelse
POST /api/TsKunder/TsKundeEndret
POST /api/UpdateOppdragWithMissingData/UpdateOppdragWithMissingTsKunde
POST /api/User/logout
POST /api/Utsettelser
PUT /api/Oppdrag/deaktiver-by-epd/{epdNr}
Open service 20.50.2.68:443 · orionapi.tradesolution.no
2026-01-23 14:04
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Fri, 23 Jan 2026 14:05:08 GMT Server: Kestrel Location: /swagger Request-Context: appId=cid-v1:c3d92d33-d8dc-4bde-bca5-a4e30a951a4e
Open service 20.50.2.68:80 · orionapi.tradesolution.no
2026-01-10 20:55
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Sat, 10 Jan 2026 20:56:49 GMT Location: https://orionapi.tradesolution.no/
Open service 20.50.2.68:443 · orionapi.tradesolution.no
2026-01-10 20:55
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Sat, 10 Jan 2026 20:56:49 GMT Server: Kestrel Location: /swagger Request-Context: appId=cid-v1:c3d92d33-d8dc-4bde-bca5-a4e30a951a4e