Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d60bca305a6027551fc0a8cc494b8c1418cacd10128
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths:
GET /Structures/ERTs
GET /Structures/ERTs/ProvisionedProperties
GET /Structures/PingPlug
GET /Structures/ProvisionedStructureTypes
GET /Structures/ProvisioningBehaviour
GET /Structures/SJFlats
GET /Structures/SJFlats/ProvisionedProperties
GET /Structures/UEFlats
GET /Structures/UEFlats/ProvisionedProperties
GET /Structures/UPFlats
GET /Structures/UPFlats/ProvisionedProperties
GET /Structures/WebServiceContractVersion
GET /Structures/WebServiceEnvironment
GET /Structures/WebServiceVersion
GET /Users/PingPlug
GET /Users/PlugLogsDirectoryPath
GET /Users/ProvisioningBehaviour
GET /Users/WebServiceContractVersion
GET /Users/WebServiceEnvironment
GET /Users/WebServiceVersion
GET /Users/{aruApplicationCode}/ApplicationUsers
GET /Users/{aruApplicationCode}/{structureType}/ProvisionedProperties
POST /Structures/BeginSynchronization
POST /Structures/EndSynchronization
POST /Structures/PlugLogsDirectoryPath
POST /Users/{aruApplicationCode}/BeginSynchronization
POST /Users/{aruApplicationCode}/EndSynchronization
PUT /Structures/ERTs/{id}
PUT /Structures/SJFlats/{id}
PUT /Structures/UEFlats/{id}
PUT /Structures/UPFlats/{id}
PUT /Users/{aruApplicationCode}/ApplicationUsers/{id}
Open service 23.36.162.207:443 · prd-cachingplugmds.csp-digital.com
2026-01-23 15:27
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 23 Jan 2026 15:27:16 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 23 Jan 2026 15:27:16 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=13 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1769182035908_399431118_750541265_1692_13160_150_302_-";dur=1
Open service 23.36.162.207:443 · prd-cachingplugmds.csp-digital.com
2026-01-09 15:43
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 09 Jan 2026 15:43:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 09 Jan 2026 15:43:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=88 Server-Timing: origin; dur=9 Server-Timing: ak_p; desc="1767973431113_399431118_3477669202_9681_28576_99_269_-";dur=1
Open service 2.16.183.15:443 · prd-cachingplugmds.csp-digital.com
2026-01-02 16:47
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 02 Jan 2026 16:47:18 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:47:18 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=36 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1767372438332_34610638_3412419209_3766_6767_171_343_-";dur=1
Open service 2a02:26f0:3500:18::1724:a289:80 · prd-cachingplugmds.csp-digital.com
2026-01-02 16:47
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingplugmds.csp-digital.com Expires: Fri, 02 Jan 2026 16:47:21 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:47:21 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=47 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1767372441347_388276361_2325093979_4839_11430_262_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.183.14:80 · prd-cachingplugmds.csp-digital.com
2026-01-02 16:47
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingplugmds.csp-digital.com Expires: Fri, 02 Jan 2026 16:47:20 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:47:20 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=7 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1767372440197_34610638_3412426031_1197_5788_17_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.183.15:80 · prd-cachingplugmds.csp-digital.com
2026-01-02 16:47
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingplugmds.csp-digital.com Expires: Fri, 02 Jan 2026 16:47:20 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:47:20 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=8 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1767372440126_34610639_3521890908_1182_5847_17_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:3500:18::1724:a289:443 · prd-cachingplugmds.csp-digital.com
2026-01-02 16:47
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 02 Jan 2026 16:47:18 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:47:18 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=19 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1767372438149_388276361_2325087878_2359_14389_83_190_-";dur=1
Open service 2a02:26f0:3500:18::1724:a290:80 · prd-cachingplugmds.csp-digital.com
2026-01-02 16:47
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingplugmds.csp-digital.com Expires: Fri, 02 Jan 2026 16:47:20 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:47:20 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=13 Server-Timing: origin; dur=1 Server-Timing: ak_p; desc="1767372440125_388276368_2222603733_1339_13214_14_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.183.14:443 · prd-cachingplugmds.csp-digital.com
2026-01-02 16:47
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 02 Jan 2026 16:47:17 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:47:17 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=10 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1767372437167_34610638_3412412996_1310_6258_15_32_-";dur=1
Open service 2a02:26f0:3500:18::1724:a290:443 · prd-cachingplugmds.csp-digital.com
2026-01-02 16:47
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Fri, 02 Jan 2026 16:47:17 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Fri, 02 Jan 2026 16:47:17 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=15 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1767372437264_388276361_2325085761_1639_14744_0_9_-";dur=1
Open service 2.16.204.90:443 · prd-cachingplugmds.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:49 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:49 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=55 Server-Timing: origin; dur=9 Server-Timing: ak_p; desc="1766475589411_34610515_1182609565_6372_11361_169_388_-";dur=1
Open service 2.16.204.90:80 · prd-cachingplugmds.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingplugmds.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:52 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:52 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=8 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1766475592084_34610522_1281882708_1114_13466_156_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:ab00::214:8e2b:443 · prd-cachingplugmds.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:48 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:48 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=34 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1766475588417_34901543_492517566_3826_20669_6_70_-";dur=1
Open service 2a02:26f0:ab00::214:8e2b:80 · prd-cachingplugmds.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingplugmds.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=9 Server-Timing: origin; dur=1 Server-Timing: ak_p; desc="1766475591418_34901543_492520764_1049_14290_19_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2a02:26f0:ab00::214:8e12:80 · prd-cachingplugmds.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingplugmds.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=29 Server-Timing: origin; dur=3 Server-Timing: ak_p; desc="1766475591353_34901518_474764663_3247_25231_14_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.204.70:80 · prd-cachingplugmds.csp-digital.com
2025-12-23 07:39
HTTP/1.1 308 Permanent Redirect Content-Type: text/html Content-Length: 164 Location: https://prd-cachingplugmds.csp-digital.com Expires: Tue, 23 Dec 2025 07:39:51 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:51 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=10 Server-Timing: origin; dur=2 Server-Timing: ak_p; desc="1766475591620_34610502_1296825577_1189_14091_87_0_-";dur=1 Page title: 308 Permanent Redirect <html> <head><title>308 Permanent Redirect</title></head> <body> <center><h1>308 Permanent Redirect</h1></center> <hr><center>nginx</center> </body> </html>
Open service 2.16.204.70:443 · prd-cachingplugmds.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:48 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:48 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=52 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1766475588441_34610523_1469172809_5608_17368_22_103_-";dur=1
Open service 2a02:26f0:ab00::214:8e12:443 · prd-cachingplugmds.csp-digital.com
2025-12-23 07:39
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 07:39:48 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 07:39:48 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=207 Server-Timing: origin; dur=5 Server-Timing: ak_p; desc="1766475588358_34901543_492517444_21228_20538_1_13_-";dur=1
Open service 23.36.162.207:443 · prd-cachingplugmds.csp-digital.com
2025-12-23 04:16
HTTP/1.1 404 Not Found Content-Length: 0 Strict-Transport-Security: max-age=31536000; includeSubDomains Expires: Tue, 23 Dec 2025 04:16:53 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 23 Dec 2025 04:16:53 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=10 Server-Timing: origin; dur=4 Server-Timing: ak_p; desc="1766463413158_399431116_1205587899_1420_11288_164_331_-";dur=1