Kestrel
tcp/443 tcp/80
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549521c07ba276d7f9dbee4ba9837846b2dd0a627dd
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /assignments
GET /assignments/{id}
GET /assignments/{id}/events
GET /batches
GET /batches/{id}
GET /batches/{id}/events
GET /companies
GET /companies/{id}
GET /companies/{id}/events
GET /ordercreationrules
GET /ordercreationrules/testpattern
GET /ordercreationrules/{id}
GET /ordercreationrules/{id}/events
GET /ordercreationrules/{id}/match
GET /orderprices
GET /orderprices/{orderId}
GET /orders
GET /orders/prototype/{orderCreationRuleId}
GET /orders/{id}
GET /orders/{id}/events
GET /orders/{id}/relations
GET /ordertemplates
GET /ordertemplates/{id}
GET /ordertemplates/{id}/events
GET /ordertemplates/{id}/relations
GET /priceitems
GET /priceitems/{id}
GET /priceitems/{id}/events
GET /pricelists
GET /pricelists/{id}
GET /pricelists/{id}/events
GET /products
GET /products/{id}
GET /products/{id}/events
GET /projects
GET /projects/{id}
GET /projects/{id}/events
GET /skills
GET /skills/{id}
GET /skills/{id}/events
POST /orders/{id}/actions/{action}
POST /orders/{id}/changestate
POST /orders/{id}/relations/{relationName}
POST /orders/{id}/startnextsuborder
POST /orders/{id}/suborders
POST /orders/{id}/workflows
POST /ordertemplates/{id}/actions/{action}
POST /ordertemplates/{id}/changestate
POST /ordertemplates/{id}/relations/{relationName}
PUT /orders/{id}/entitystatus
PUT /orders/{id}/relations/{relationId}
PUT /ordertemplates/{id}/relations/{relationId}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549521c07ba276d7f9dbee4ba9837846b2d823f9e8c
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /assignments
GET /assignments/{id}
GET /assignments/{id}/events
GET /batches
GET /batches/{id}
GET /batches/{id}/events
GET /companies
GET /companies/{id}
GET /companies/{id}/events
GET /ordercreationrules
GET /ordercreationrules/testpattern
GET /ordercreationrules/{id}
GET /ordercreationrules/{id}/events
GET /ordercreationrules/{id}/match
GET /orderprices
GET /orderprices/{orderId}
GET /orders
GET /orders/prototype/{orderCreationRuleId}
GET /orders/{id}
GET /orders/{id}/events
GET /orders/{id}/relations
GET /ordertemplates
GET /ordertemplates/{id}
GET /ordertemplates/{id}/events
GET /ordertemplates/{id}/relations
GET /priceitems
GET /priceitems/{id}
GET /priceitems/{id}/events
GET /pricelists
GET /pricelists/{id}
GET /pricelists/{id}/events
GET /products
GET /products/{id}
GET /products/{id}/events
GET /projects
GET /projects/{id}
GET /projects/{id}/events
GET /skills
GET /skills/{id}
GET /skills/{id}/events
POST /orders/{id}/actions/{action}
POST /orders/{id}/changestate
POST /orders/{id}/relations/{relationName}
POST /orders/{id}/startnextsuborder
POST /orders/{id}/suborders
POST /orders/{id}/workflows
POST /ordertemplates/{id}/actions/{action}
POST /ordertemplates/{id}/changestate
POST /ordertemplates/{id}/relations/{relationName}
PUT /orders/{id}/relations/{relationId}
PUT /ordertemplates/{id}/relations/{relationId}
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549521c07ba276d7f9dbee4ba9837846b2dd0a627dd
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /assignments
GET /assignments/{id}
GET /assignments/{id}/events
GET /batches
GET /batches/{id}
GET /batches/{id}/events
GET /companies
GET /companies/{id}
GET /companies/{id}/events
GET /ordercreationrules
GET /ordercreationrules/testpattern
GET /ordercreationrules/{id}
GET /ordercreationrules/{id}/events
GET /ordercreationrules/{id}/match
GET /orderprices
GET /orderprices/{orderId}
GET /orders
GET /orders/prototype/{orderCreationRuleId}
GET /orders/{id}
GET /orders/{id}/events
GET /orders/{id}/relations
GET /ordertemplates
GET /ordertemplates/{id}
GET /ordertemplates/{id}/events
GET /ordertemplates/{id}/relations
GET /priceitems
GET /priceitems/{id}
GET /priceitems/{id}/events
GET /pricelists
GET /pricelists/{id}
GET /pricelists/{id}/events
GET /products
GET /products/{id}
GET /products/{id}/events
GET /projects
GET /projects/{id}
GET /projects/{id}/events
GET /skills
GET /skills/{id}
GET /skills/{id}/events
POST /orders/{id}/actions/{action}
POST /orders/{id}/changestate
POST /orders/{id}/relations/{relationName}
POST /orders/{id}/startnextsuborder
POST /orders/{id}/suborders
POST /orders/{id}/workflows
POST /ordertemplates/{id}/actions/{action}
POST /ordertemplates/{id}/changestate
POST /ordertemplates/{id}/relations/{relationName}
PUT /orders/{id}/entitystatus
PUT /orders/{id}/relations/{relationId}
PUT /ordertemplates/{id}/relations/{relationId}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549521c07ba276d7f9dbee4ba9837846b2d823f9e8c
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /assignments
GET /assignments/{id}
GET /assignments/{id}/events
GET /batches
GET /batches/{id}
GET /batches/{id}/events
GET /companies
GET /companies/{id}
GET /companies/{id}/events
GET /ordercreationrules
GET /ordercreationrules/testpattern
GET /ordercreationrules/{id}
GET /ordercreationrules/{id}/events
GET /ordercreationrules/{id}/match
GET /orderprices
GET /orderprices/{orderId}
GET /orders
GET /orders/prototype/{orderCreationRuleId}
GET /orders/{id}
GET /orders/{id}/events
GET /orders/{id}/relations
GET /ordertemplates
GET /ordertemplates/{id}
GET /ordertemplates/{id}/events
GET /ordertemplates/{id}/relations
GET /priceitems
GET /priceitems/{id}
GET /priceitems/{id}/events
GET /pricelists
GET /pricelists/{id}
GET /pricelists/{id}/events
GET /products
GET /products/{id}
GET /products/{id}/events
GET /projects
GET /projects/{id}
GET /projects/{id}/events
GET /skills
GET /skills/{id}
GET /skills/{id}/events
POST /orders/{id}/actions/{action}
POST /orders/{id}/changestate
POST /orders/{id}/relations/{relationName}
POST /orders/{id}/startnextsuborder
POST /orders/{id}/suborders
POST /orders/{id}/workflows
POST /ordertemplates/{id}/actions/{action}
POST /ordertemplates/{id}/changestate
POST /ordertemplates/{id}/relations/{relationName}
PUT /orders/{id}/relations/{relationId}
PUT /ordertemplates/{id}/relations/{relationId}
Open service 13.80.19.74:80 · prod-j1-orders.junecomet.com
2026-01-23 09:03
HTTP/1.1 403 Site Disabled
Content-Length: 1148
Connection: close
Content-Type: text/html
Date: Fri, 23 Jan 2026 09:04:10 GMT
Page title: Web App - Unavailable
<!DOCTYPE html><html><head><title>Web App - Unavailable</title><style type="text/css">html{height:100%;width:100%;}#feature{width:960px;margin:95px auto 0 auto;overflow:auto;}#content{font-family:"Segoe UI";font-weight:normal;font-size:22px;color:#fff;float:left;width:460px;margin-top:68px;margin-left:0px;vertical-align:middle;}#content h1{font-family:"Segoe UI Light";color:#fff;font-weight:normal;font-size:60px;line-height:48pt;width:800px;}p a,p a:visited,p a:active,p a:hover{color:#fff;}</style></head><body bgcolor="#00abec"><div id="feature"><div id="content"><h1 id="unavailable">Error 403 - This web app is stopped.</h1><p id="tryAgain">The web app you have attempted to reach is currently stopped and does not accept any requests. Please try to reload the page or visit it again soon.</p><p id="toAdmin">If you are the web app administrator, please find the common 403 error scenarios and resolution <a href="https://go.microsoft.com/fwlink/?linkid=2095007" target="_blank">here</a>. For further troubleshooting tools and recommendations, please visit <a href="https://portal.azure.com/">Azure Portal</a>.</p></div></div></body></html>
Open service 13.80.19.74:443 · prod-j1-orders.junecomet.com
2026-01-23 04:30
HTTP/1.1 403 Site Disabled
Content-Length: 1148
Connection: close
Content-Type: text/html
Date: Fri, 23 Jan 2026 04:31:26 GMT
Page title: Web App - Unavailable
<!DOCTYPE html><html><head><title>Web App - Unavailable</title><style type="text/css">html{height:100%;width:100%;}#feature{width:960px;margin:95px auto 0 auto;overflow:auto;}#content{font-family:"Segoe UI";font-weight:normal;font-size:22px;color:#fff;float:left;width:460px;margin-top:68px;margin-left:0px;vertical-align:middle;}#content h1{font-family:"Segoe UI Light";color:#fff;font-weight:normal;font-size:60px;line-height:48pt;width:800px;}p a,p a:visited,p a:active,p a:hover{color:#fff;}</style></head><body bgcolor="#00abec"><div id="feature"><div id="content"><h1 id="unavailable">Error 403 - This web app is stopped.</h1><p id="tryAgain">The web app you have attempted to reach is currently stopped and does not accept any requests. Please try to reload the page or visit it again soon.</p><p id="toAdmin">If you are the web app administrator, please find the common 403 error scenarios and resolution <a href="https://go.microsoft.com/fwlink/?linkid=2095007" target="_blank">here</a>. For further troubleshooting tools and recommendations, please visit <a href="https://portal.azure.com/">Azure Portal</a>.</p></div></div></body></html>
Open service 13.80.19.74:80 · prod-j1-orders.junecomet.com
2026-01-10 00:56
HTTP/1.1 307 Temporary Redirect Content-Length: 0 Connection: close Date: Sat, 10 Jan 2026 00:56:59 GMT Server: Kestrel Location: https://prod-j1-orders.junecomet.com/ X-Powered-By: ASP.NET
Open service 13.80.19.74:443 · prod-j1-orders.junecomet.com
2026-01-09 20:17
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 09 Jan 2026 20:18:43 GMT Server: Kestrel X-Powered-By: ASP.NET
Open service 13.80.19.74:443 · prod-j1-orders.junecomet.com
2026-01-03 00:49
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Sat, 03 Jan 2026 00:49:56 GMT Server: Kestrel X-Powered-By: ASP.NET
Open service 13.80.19.74:80 · prod-j1-orders.junecomet.com
2026-01-02 19:02
HTTP/1.1 307 Temporary Redirect Content-Length: 0 Connection: close Date: Fri, 02 Jan 2026 19:02:05 GMT Server: Kestrel Location: https://prod-j1-orders.junecomet.com/ X-Powered-By: ASP.NET
Open service 13.80.19.74:443 · prod-j1-orders.junecomet.com
2025-12-23 07:51
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Tue, 23 Dec 2025 07:51:44 GMT Server: Kestrel X-Powered-By: ASP.NET
Open service 13.80.19.74:80 · prod-j1-orders.junecomet.com
2025-12-22 13:46
HTTP/1.1 307 Temporary Redirect Content-Length: 0 Connection: close Date: Mon, 22 Dec 2025 13:46:46 GMT Server: Kestrel Location: https://prod-j1-orders.junecomet.com/ X-Powered-By: ASP.NET