Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549db8acb370cdb55a8f7c45951c393988ba6ad2e8f
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/v1/Diagnostic/version
GET /api/v1/Tenants
GET /api/v1/Tenants/{id}
GET /{tenant}/api/v1/Documents/readyToDownload
GET /{tenant}/api/v1/TenantConfiguration
POST /{tenant}/api/v1/Documents/{documentId}/read-confirmation
Open service 13.107.213.60:443 · pef-preview.unit4teta.com
2026-01-23 10:18
HTTP/1.1 302 Found Date: Fri, 23 Jan 2026 10:18:12 GMT Content-Length: 0 Connection: close Location: https://s-eu-ids1-preview.unit4cloud.com/identity/connect/authorize?client_id=u4t-pef-integration&redirect_uri=https%3A%2F%2Fpef-preview.unit4teta.com%2Fsignin-oidc&response_type=code%20id_token&scope=openid%20profile%20u4am-public-api%20teta_pef&response_mode=form_post&nonce=639047602920984971.YWNmMjNjNDktOTcyMi00YzExLWEyZGItMTdiNGUzNzI1ODBmMTNmZTFmMzItM2UxYy00YTNhLTg4YjUtMDljMGY0OWU5NzY1&state=CfDJ8Ah4nn7_MpROkFFkyovefd96lFhUvMFsCiOLIFEXXP7ABjz4m6jpXeQY2t2oYWfhX1VW63gsiZBrNoSlH54kYQiKpFC4k_kMpisYuqR5GxSiBYOvjNyaoLfGp0SLsqFd2t3n01piVHZrY_3f9bLYilPjl9Z4EILwsuNHmgF7FJKgzCI26KilBXSozMJNNF7oOPrHkZsFT2Mxnvfi_EmoQ2k_NvwJnphfTorZDIA-H4EoeodS_9bqtpyUiqHo9zYgQ62lSPkH6pNufht1xVM0PHxelty2ov7430PsZi2aikkXrE026VwVq5MtJIya7IERkg Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8Ah4nn7_MpROkFFkyovefd9nPAjwRqDuxbW621thqxqoRCAMZ0sepe1VXfAm1Yovgp7KWbu00UtqB0FkSNJLPE-Lm2Sexj5TFxbWzLUojX_8DMoFDU0gDqqgzJcWIVmoMMwWQvziTFKavDDxKBaved7dFfaX3tJrTbD7hD4RPDCvxNih15WEnMoWdoQknD-K1VY4eJ8_1iCO_DZ0C-E-KAZaU1HI70z2RbTSYYTfQNqiIac_w_qBWQjx1vmStHZmmLY2SuXgnU__n3nSoUWrI-8=N; expires=Fri, 23 Jan 2026 10:33:12 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: .AspNetCore.Correlation.oidc.FlU-fqliGVjkUjSRwAQ58uRBiBkJZ-VFvtxLRroHlxM=N; expires=Fri, 23 Jan 2026 10:33:12 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: ARRAffinity=9bcbe44455e5f2232684c8ab58596c72109fd98105b42c7cde3064527a6492dd;Path=/;HttpOnly;Secure;Domain=s-eun-teta-pef-prev.azurewebsites.net Set-Cookie: ARRAffinitySameSite=9bcbe44455e5f2232684c8ab58596c72109fd98105b42c7cde3064527a6492dd;Path=/;HttpOnly;SameSite=None;Secure;Domain=s-eun-teta-pef-prev.azurewebsites.net Strict-Transport-Security: max-age=2592000 Request-Context: appId=cid-v1:eaf62f34-50e8-49ae-a156-56a5338726f4 X-Powered-By: ASP.NET x-azure-ref: 20260123T101812Z-r17955489d5qlzjthC1FRAwrm40000001zg00000000079e5 X-Cache: CONFIG_NOCACHE
Open service 13.107.213.60:443 · pef-preview.unit4teta.com
2026-01-10 09:16
HTTP/1.1 302 Found Date: Sat, 10 Jan 2026 09:16:54 GMT Content-Length: 0 Connection: close Location: https://s-eu-ids1-preview.unit4cloud.com/identity/connect/authorize?client_id=u4t-pef-integration&redirect_uri=https%3A%2F%2Fpef-preview.unit4teta.com%2Fsignin-oidc&response_type=code%20id_token&scope=openid%20profile%20u4am-public-api%20teta_pef&response_mode=form_post&nonce=639036334144400364.OTJkOTI2ZGMtMzBmNy00ZDM2LWJhMzctMjZjZGJlNzJjM2U2YmMzZjU4NmEtYTcwOS00YjZlLTk0YmEtYmVkOGIxNTkwMDk3&state=CfDJ8Ah4nn7_MpROkFFkyovefd-Pi_Q2tc3fiBQlDrwTqgml-LKpzYs53Cf4Qjh6Sag0STMNrQIOL6RlA6Q2TKyr86B3PrZVMOvvT-VXyGE0VdL93yvUA5SAFoJzgVkhG3y0iMu0jFaHTiZceatEWfM1Mzw2kbuRhWoaovhonYpne-d4cUZwh70Mq-8jzwMYIDiPgFtfFtLM2ZLG9STvZSp871om_ZWiTGSo-IXVptXmFs-7buzw_6cMeKiWo86H3M3x00EcwVaMvJgnFolv30j0wm2xSJB0Jwk1MAYI9oA2CEi95TzaPaUiQszYyqUmDdxa6w Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8Ah4nn7_MpROkFFkyovefd8kxWhnXYvJeYjMbCtoQXPqTXwZr744h57JDnh7cNRtdKXNnuWuLLw9kymQ2gKJVuHaHohF0l9SBVjGm5IqNo08IML6YMS3uy6Q2OpdQ5funBZ92tBrfZQIeXrPk8QjAEV44f0LfwvdKqPSfouGFsIhB_79CQshlnNOI-be8gAcm0788eDevC9YR8IkvBs1BsEyB0zjTF1_ZvhUTEWvObHtsOhZZ7MScXRrAizGPbHSl--xSPbbg7NCqXPg9L3heD8=N; expires=Sat, 10 Jan 2026 09:31:54 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: .AspNetCore.Correlation.oidc.0C5cKcC1hIXUW3_Vy7btgydOauQ5yzMMa2d-pV4Z2eo=N; expires=Sat, 10 Jan 2026 09:31:54 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: ARRAffinity=a6fb9d4a7fdfa69038faad54751d923a0aba44298b745eed4cf3d208a9945c3c;Path=/;HttpOnly;Secure;Domain=s-eun-teta-pef-prev.azurewebsites.net Set-Cookie: ARRAffinitySameSite=a6fb9d4a7fdfa69038faad54751d923a0aba44298b745eed4cf3d208a9945c3c;Path=/;HttpOnly;SameSite=None;Secure;Domain=s-eun-teta-pef-prev.azurewebsites.net Strict-Transport-Security: max-age=2592000 Request-Context: appId=cid-v1:eaf62f34-50e8-49ae-a156-56a5338726f4 X-Powered-By: ASP.NET x-azure-ref: 20260110T091654Z-r17955489d5b97ddhC1FRAqv8w0000000ch000000000f4bc X-Cache: CONFIG_NOCACHE