Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549e8d97bb70493dbcbed0d93ebed0d93ebed0d93eb
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /.well-known/keys
GET /.well-known/openid-configuration
POST /api/Signing/{clientId}
Open service 2.16.204.70:443 · prd-cachingapiissuer.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:49 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:49 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=10 Server-Timing: origin; dur=16 Server-Timing: ak_p; desc="1766475589013_34610502_1296815193_2549_14538_94_201_-";dur=1
Open service 2a02:26f0:ab00::214:8e2b:80 · prd-cachingapiissuer.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingapiissuer.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=12 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1766475591557_34901543_492520922_1445_14996_14_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.204.90:80 · prd-cachingapiissuer.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingapiissuer.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=37 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1766475591492_34610522_1281880571_3991_9198_12_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:ab00::214:8e2b:443 · prd-cachingapiissuer.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:49 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:49 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=24 Server-Timing: origin; dur=83 Server-Timing: ak_p; desc="1766475588987_34901518_474762343_10666_14538_80_170_-";dur=1
Open service 2.16.204.90:443 · prd-cachingapiissuer.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:49 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:49 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=42 Server-Timing: origin; dur=9 Server-Timing: ak_p; desc="1766475589372_34610515_1182609224_5093_12992_164_334_-";dur=1
Open service 2.16.204.70:80 · prd-cachingapiissuer.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingapiissuer.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=14 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1766475591411_34610502_1296824572_1799_11702_18_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:ab00::214:8e12:80 · prd-cachingapiissuer.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingapiissuer.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=11 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1766475591728_34901518_474765025_1255_12591_97_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:ab00::214:8e12:443 · prd-cachingapiissuer.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:48 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:48 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=47 Server-Timing: origin; dur=1 Server-Timing: ak_p; desc="1766475588357_34901518_474761637_4656_16813_0_32_-";dur=1