Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549abefabaabd61a02a001e57080516f74086e2759e
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/adminUsers/current
GET /api/clients
GET /api/clients/{id}
GET /api/identityProviders/oidc
GET /api/identityProviders/oidc/{scheme}
GET /api/identityProviders/wsfed
GET /api/identityProviders/wsfed/{scheme}
GET /api/resources
GET /api/resources/{name}
GET /api/scopes
GET /api/scopes/{name}
PUT /api/adminUsers/password
Open service 13.80.19.74:443 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-26 01:13
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Mon, 26 Jan 2026 01:13:29 GMT Cache-Control: no-store, no-cache, must-revalidate Location: /grants Pragma: no-cache Set-Cookie: ARRAffinity=aef6da079761d63dfc61692839d1812ac4e820a415fb4190887f05341e339787;Path=/;HttpOnly;Secure;Domain=rc-16-41-energyinstall-slas.syndev.dnv.com Set-Cookie: ARRAffinitySameSite=aef6da079761d63dfc61692839d1812ac4e820a415fb4190887f05341e339787;Path=/;HttpOnly;SameSite=None;Secure;Domain=rc-16-41-energyinstall-slas.syndev.dnv.com Strict-Transport-Security: max-age=31536000; includeSubDomains Request-Context: appId=cid-v1:f5402bdc-4057-42c7-933a-499f9f1a63f8 X-Frame-Options: DENY Referrer-Policy: no-referrer X-Content-Type-Options: nosniff X-Download-Options: noopen X-Robots-Tag: noindex, nofollow Content-Security-Policy: default-src 'none'; img-src 'self'; script-src 'none'; style-src 'none'; base-uri 'none'; object-src 'none'; connect-src 'none'; font-src 'none'; frame-src 'none'; form-action 'none'; manifest-src 'none'; media-src 'none'; worker-src 'none' X-Permitted-Cross-Domain-Policies: none Permissions-Policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),encrypted-media=(),fullscreen=(),gamepad=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),sync-xhr=(self),usb=(),screen-wake-lock=(),web-share=(),xr-spatial-tracking=()
Open service 13.80.19.74:80 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-26 01:13
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 26 Jan 2026 01:13:30 GMT Location: https://rc-16-41-energyinstall-slas.syndev.dnv.com/
Open service 20.105.216.40:443 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-23 16:38
HTTP/1.1 404 Site Not Found
Content-Length: 2667
Connection: close
Content-Type: text/html
Date: Fri, 23 Jan 2026 16:38:31 GMT
Page title: Microsoft Azure Web App - Error 404
<!DOCTYPE html>
<html>
<head>
<title>Microsoft Azure Web App - Error 404</title>
<style type="text/css">
html {
height: 100%;
width: 100%;
}
#feature {
width: 960px;
margin: 75px auto 0 auto;
overflow: auto;
}
#content {
font-family: "Segoe UI";
font-weight: normal;
font-size: 22px;
color: #ffffff;
float: left;
margin-top: 68px;
margin-left: 0px;
vertical-align: middle;
}
#content h1 {
font-family: "Segoe UI Light";
color: #ffffff;
font-weight: normal;
font-size: 60px;
line-height: 48pt;
width: 800px;
}
a, a:visited, a:active, a:hover {
color: #ffffff;
}
#content a.button {
background: #0DBCF2;
border: 1px solid #FFFFFF;
color: #FFFFFF;
display: inline-block;
font-family: Segoe UI;
font-size: 24px;
line-height: 46px;
margin-top: 10px;
padding: 0 15px 3px;
text-decoration: none;
}
#content a.button img {
float: right;
padding: 10px 0 0 15px;
}
#content a.button:hover {
background: #1C75BC;
}
</style>
<script type="text/javascript">
function toggle_visibility(id) {
var e = document.getElementById(id);
if (e.style.display == 'block')
e.style.display = 'none';
else
e.style.display = 'block';
}
</script>
</head>
<body bgcolor="#00abec">
<div id="feature">
<div id="content">
<h1>404 Web Site not found.</h1>
<p>You may be seeing this error due to one of the reasons listed below :</p>
<ul>
<li>Custom domain has not been configured inside Azure. See <a href="https://go.microsoft.com/fwlink/?linkid=2194614">how to map an existing domain</a> to resolve this.</li>
<li>Client cache is still pointing the domain to old IP address. Clear the cache by running the command <i>ipconfig/flushdns.</i></li>
</ul>
<p>Checkout <a href="https://go.microsoft.com/fwlink/?linkid=2194451">App Service Domain FAQ</a> for more questions.</p>
</div>
</div>
</body>
</html>
Open service 13.80.19.74:80 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-12 01:10
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 12 Jan 2026 01:11:08 GMT Location: https://rc-16-41-energyinstall-slas.syndev.dnv.com/
Open service 13.80.19.74:443 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-12 01:10
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Mon, 12 Jan 2026 01:11:09 GMT Cache-Control: no-store, no-cache, must-revalidate Location: /grants Pragma: no-cache Set-Cookie: ARRAffinity=aef6da079761d63dfc61692839d1812ac4e820a415fb4190887f05341e339787;Path=/;HttpOnly;Secure;Domain=rc-16-41-energyinstall-slas.syndev.dnv.com Set-Cookie: ARRAffinitySameSite=aef6da079761d63dfc61692839d1812ac4e820a415fb4190887f05341e339787;Path=/;HttpOnly;SameSite=None;Secure;Domain=rc-16-41-energyinstall-slas.syndev.dnv.com Strict-Transport-Security: max-age=31536000; includeSubDomains Request-Context: appId=cid-v1:f5402bdc-4057-42c7-933a-499f9f1a63f8 X-Frame-Options: DENY Referrer-Policy: no-referrer X-Content-Type-Options: nosniff X-Download-Options: noopen X-Robots-Tag: noindex, nofollow Content-Security-Policy: default-src 'none'; img-src 'self'; script-src 'none'; style-src 'none'; base-uri 'none'; object-src 'none'; connect-src 'none'; font-src 'none'; frame-src 'none'; form-action 'none'; manifest-src 'none'; media-src 'none'; worker-src 'none' X-Permitted-Cross-Domain-Policies: none Permissions-Policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),encrypted-media=(),fullscreen=(),gamepad=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),sync-xhr=(self),usb=(),screen-wake-lock=(),web-share=(),xr-spatial-tracking=()
Open service 20.105.216.40:443 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-09 11:10
HTTP/1.1 404 Site Not Found
Content-Length: 2667
Connection: close
Content-Type: text/html
Date: Fri, 09 Jan 2026 11:11:16 GMT
Page title: Microsoft Azure Web App - Error 404
<!DOCTYPE html>
<html>
<head>
<title>Microsoft Azure Web App - Error 404</title>
<style type="text/css">
html {
height: 100%;
width: 100%;
}
#feature {
width: 960px;
margin: 75px auto 0 auto;
overflow: auto;
}
#content {
font-family: "Segoe UI";
font-weight: normal;
font-size: 22px;
color: #ffffff;
float: left;
margin-top: 68px;
margin-left: 0px;
vertical-align: middle;
}
#content h1 {
font-family: "Segoe UI Light";
color: #ffffff;
font-weight: normal;
font-size: 60px;
line-height: 48pt;
width: 800px;
}
a, a:visited, a:active, a:hover {
color: #ffffff;
}
#content a.button {
background: #0DBCF2;
border: 1px solid #FFFFFF;
color: #FFFFFF;
display: inline-block;
font-family: Segoe UI;
font-size: 24px;
line-height: 46px;
margin-top: 10px;
padding: 0 15px 3px;
text-decoration: none;
}
#content a.button img {
float: right;
padding: 10px 0 0 15px;
}
#content a.button:hover {
background: #1C75BC;
}
</style>
<script type="text/javascript">
function toggle_visibility(id) {
var e = document.getElementById(id);
if (e.style.display == 'block')
e.style.display = 'none';
else
e.style.display = 'block';
}
</script>
</head>
<body bgcolor="#00abec">
<div id="feature">
<div id="content">
<h1>404 Web Site not found.</h1>
<p>You may be seeing this error due to one of the reasons listed below :</p>
<ul>
<li>Custom domain has not been configured inside Azure. See <a href="https://go.microsoft.com/fwlink/?linkid=2194614">how to map an existing domain</a> to resolve this.</li>
<li>Client cache is still pointing the domain to old IP address. Clear the cache by running the command <i>ipconfig/flushdns.</i></li>
</ul>
<p>Checkout <a href="https://go.microsoft.com/fwlink/?linkid=2194451">App Service Domain FAQ</a> for more questions.</p>
</div>
</div>
</body>
</html>
Open service 13.80.19.74:443 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-05 01:12
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Mon, 05 Jan 2026 01:12:29 GMT Cache-Control: no-store, no-cache, must-revalidate Location: /grants Pragma: no-cache Set-Cookie: ARRAffinity=aef6da079761d63dfc61692839d1812ac4e820a415fb4190887f05341e339787;Path=/;HttpOnly;Secure;Domain=rc-16-41-energyinstall-slas.syndev.dnv.com Set-Cookie: ARRAffinitySameSite=aef6da079761d63dfc61692839d1812ac4e820a415fb4190887f05341e339787;Path=/;HttpOnly;SameSite=None;Secure;Domain=rc-16-41-energyinstall-slas.syndev.dnv.com Strict-Transport-Security: max-age=31536000; includeSubDomains Request-Context: appId=cid-v1:f5402bdc-4057-42c7-933a-499f9f1a63f8 X-Frame-Options: DENY Referrer-Policy: no-referrer X-Content-Type-Options: nosniff X-Download-Options: noopen X-Robots-Tag: noindex, nofollow Content-Security-Policy: default-src 'none'; img-src 'self'; script-src 'none'; style-src 'none'; base-uri 'none'; object-src 'none'; connect-src 'none'; font-src 'none'; frame-src 'none'; form-action 'none'; manifest-src 'none'; media-src 'none'; worker-src 'none' X-Permitted-Cross-Domain-Policies: none Permissions-Policy: accelerometer=(),autoplay=(),camera=(),display-capture=(),encrypted-media=(),fullscreen=(),gamepad=(),geolocation=(),gyroscope=(),magnetometer=(),microphone=(),midi=(),payment=(),picture-in-picture=(),publickey-credentials-get=(),sync-xhr=(self),usb=(),screen-wake-lock=(),web-share=(),xr-spatial-tracking=()
Open service 13.80.19.74:80 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-05 01:12
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 05 Jan 2026 01:12:18 GMT Location: https://rc-16-41-energyinstall-slas.syndev.dnv.com/
Open service 20.105.216.40:443 · rc-16-41-energyinstall-slas.syndev.dnv.com
2026-01-02 02:36
HTTP/1.1 404 Site Not Found
Content-Length: 2667
Connection: close
Content-Type: text/html
Date: Fri, 02 Jan 2026 02:36:30 GMT
Page title: Microsoft Azure Web App - Error 404
<!DOCTYPE html>
<html>
<head>
<title>Microsoft Azure Web App - Error 404</title>
<style type="text/css">
html {
height: 100%;
width: 100%;
}
#feature {
width: 960px;
margin: 75px auto 0 auto;
overflow: auto;
}
#content {
font-family: "Segoe UI";
font-weight: normal;
font-size: 22px;
color: #ffffff;
float: left;
margin-top: 68px;
margin-left: 0px;
vertical-align: middle;
}
#content h1 {
font-family: "Segoe UI Light";
color: #ffffff;
font-weight: normal;
font-size: 60px;
line-height: 48pt;
width: 800px;
}
a, a:visited, a:active, a:hover {
color: #ffffff;
}
#content a.button {
background: #0DBCF2;
border: 1px solid #FFFFFF;
color: #FFFFFF;
display: inline-block;
font-family: Segoe UI;
font-size: 24px;
line-height: 46px;
margin-top: 10px;
padding: 0 15px 3px;
text-decoration: none;
}
#content a.button img {
float: right;
padding: 10px 0 0 15px;
}
#content a.button:hover {
background: #1C75BC;
}
</style>
<script type="text/javascript">
function toggle_visibility(id) {
var e = document.getElementById(id);
if (e.style.display == 'block')
e.style.display = 'none';
else
e.style.display = 'block';
}
</script>
</head>
<body bgcolor="#00abec">
<div id="feature">
<div id="content">
<h1>404 Web Site not found.</h1>
<p>You may be seeing this error due to one of the reasons listed below :</p>
<ul>
<li>Custom domain has not been configured inside Azure. See <a href="https://go.microsoft.com/fwlink/?linkid=2194614">how to map an existing domain</a> to resolve this.</li>
<li>Client cache is still pointing the domain to old IP address. Clear the cache by running the command <i>ipconfig/flushdns.</i></li>
</ul>
<p>Checkout <a href="https://go.microsoft.com/fwlink/?linkid=2194451">App Service Domain FAQ</a> for more questions.</p>
</div>
</div>
</body>
</html>
Open service 20.105.216.40:443 · rc-16-41-energyinstall-slas.syndev.dnv.com
2025-12-22 19:28
HTTP/1.1 404 Site Not Found
Content-Length: 2667
Connection: close
Content-Type: text/html
Date: Mon, 22 Dec 2025 19:28:10 GMT
Page title: Microsoft Azure Web App - Error 404
<!DOCTYPE html>
<html>
<head>
<title>Microsoft Azure Web App - Error 404</title>
<style type="text/css">
html {
height: 100%;
width: 100%;
}
#feature {
width: 960px;
margin: 75px auto 0 auto;
overflow: auto;
}
#content {
font-family: "Segoe UI";
font-weight: normal;
font-size: 22px;
color: #ffffff;
float: left;
margin-top: 68px;
margin-left: 0px;
vertical-align: middle;
}
#content h1 {
font-family: "Segoe UI Light";
color: #ffffff;
font-weight: normal;
font-size: 60px;
line-height: 48pt;
width: 800px;
}
a, a:visited, a:active, a:hover {
color: #ffffff;
}
#content a.button {
background: #0DBCF2;
border: 1px solid #FFFFFF;
color: #FFFFFF;
display: inline-block;
font-family: Segoe UI;
font-size: 24px;
line-height: 46px;
margin-top: 10px;
padding: 0 15px 3px;
text-decoration: none;
}
#content a.button img {
float: right;
padding: 10px 0 0 15px;
}
#content a.button:hover {
background: #1C75BC;
}
</style>
<script type="text/javascript">
function toggle_visibility(id) {
var e = document.getElementById(id);
if (e.style.display == 'block')
e.style.display = 'none';
else
e.style.display = 'block';
}
</script>
</head>
<body bgcolor="#00abec">
<div id="feature">
<div id="content">
<h1>404 Web Site not found.</h1>
<p>You may be seeing this error due to one of the reasons listed below :</p>
<ul>
<li>Custom domain has not been configured inside Azure. See <a href="https://go.microsoft.com/fwlink/?linkid=2194614">how to map an existing domain</a> to resolve this.</li>
<li>Client cache is still pointing the domain to old IP address. Clear the cache by running the command <i>ipconfig/flushdns.</i></li>
</ul>
<p>Checkout <a href="https://go.microsoft.com/fwlink/?linkid=2194451">App Service Domain FAQ</a> for more questions.</p>
</div>
</div>
</body>
</html>