Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad035492a64c261ebe8e6f73c1ed0b0fa41198e72555944
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/Organizations
GET /api/Organizations/{organization}
GET /api/Organizations/{organization}/Projects/{project}
GET /api/Organizations/{organization}/Projects/{project}/VariableGroups
GET /api/Organizations/{organization}/Projects/{project}/VariableGroups/{id}
POST /api/Organizations/{organization}/VariableGroups
POST /api/Organizations/{organization}/VariableGroups/Compare
Open service 23.50.131.152:443 · prd-azdevops-api.csp-digital.com
2026-01-23 10:49
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 23 Jan 2026 10:49:09 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 23 Jan 2026 10:49:09 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=14 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1769165349479_389224207_1643926785_1708_14284_0_32_-";dur=1
Open service 23.50.131.152:443 · prd-azdevops-api.csp-digital.com
2026-01-09 16:53
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 16:53:39 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 16:53:39 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=116 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1767977619366_389224216_205487774_11950_21745_12_69_-";dur=1
Open service 23.50.131.152:443 · prd-azdevops-api.csp-digital.com
2026-01-02 17:58
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 02 Jan 2026 17:58:35 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 17:58:35 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=58 Server-Timing: origin; dur=15 Server-Timing: ak_p; desc="1767376715882_389224216_611712472_7284_8549_0_11_-";dur=1
Open service 2.16.204.83:443 · prd-azdevops-api.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:49 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:49 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=42 Server-Timing: origin; dur=6 Server-Timing: ak_p; desc="1766475589452_34610515_1182609519_4759_11875_163_337_-";dur=1
Open service 2.16.204.83:80 · prd-azdevops-api.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-azdevops-api.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=14 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1766475591910_34610515_1182617420_1579_12928_93_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:ab00::214:8e2b:443 · prd-azdevops-api.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:49 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:49 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=20 Server-Timing: origin; dur=23 Server-Timing: ak_p; desc="1766475589037_34901543_492518360_4252_12484_88_181_-";dur=1
Open service 2a02:26f0:ab00::214:8e2b:80 · prd-azdevops-api.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-azdevops-api.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=10 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1766475591681_34901543_492521113_1207_12323_78_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.204.90:443 · prd-azdevops-api.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:49 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:49 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=45 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1766475589049_34610523_1469176137_4755_12172_94_195_-";dur=1
Open service 2a02:26f0:ab00::214:8e12:443 · prd-azdevops-api.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:48 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:48 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=14 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1766475588324_34901518_474761588_1711_18783_14_44_-";dur=1
Open service 2.16.204.90:80 · prd-azdevops-api.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-azdevops-api.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=9 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1766475591214_34610522_1281879521_1081_11350_9_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:ab00::214:8e12:80 · prd-azdevops-api.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-azdevops-api.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=20 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1766475591263_34901518_474764527_2239_14982_12_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 23.50.131.152:443 · prd-azdevops-api.csp-digital.com
2025-12-23 05:32
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 05:32:53 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 05:32:53 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=8 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1766467973477_389224216_2804451545_1168_6895_0_3_-";dur=1