Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 13.107.213.60:443 · release-sessiondataaccessrules.trackmansoftball.com
2026-01-23 05:44
HTTP/1.1 302 Found Date: Fri, 23 Jan 2026 05:44:42 GMT Content-Length: 0 Connection: close Location: https://release-login.trackman.com/connect/authorize?client_id=SoftballSessionDataAccessRules&redirect_uri=https%3A%2F%2Frelease-sessiondataaccessrules.trackmansoftball.com%2Fsignin-oidc&response_type=code&scope=openid%20offline_access%20domain%3ASBSDAR%20permissions&code_challenge=htH35T79iMgb3CaWc23ZVxwOKA1WERnZ75Ha3U3IrPo&code_challenge_method=S256&response_mode=form_post&nonce=639047438825031994.ODU3ZTdkNjItN2FkOS00MzE3LTg0MDQtMmQ4YTM2YTRjM2U1ZThhOWFiMzQtNDlhNC00YWQ0LTgyMjktZTI0N2Q2ZDk0NmEx&state=CfDJ8BOu3dpzBwFIvsN1-x_vcjGAI76rIcUuQln7pYeq4NXpw7HoIwr7NHVGGvOq-POCxezeYdY5YMcWqkgoAYf43hjvWOzLa9HFQc99GLy2hKeZyGnEGVa9iHSxvvMNXG2aXLcBXQgl0rFH-OjPtK4hr2XhrQsbPmra-YH0AOu75UfKqRDok_AZzqKnqEZqbROLXakuVnDQbS0NGim4n426P-j6fxSdUlI5rWG9W-45JPEw527QXM6o-bubiWd9FupnBecuAAxexVnJwbF0HTrmp5WyO5hmUH_HBb2sVVe-pHIiIyce6Gx0sI1c-7Tyl6e57KdocDG1R9_9LWN-07NtfxLXFxV_jJkOXyfL8NiV207veGpY1iKDhmQNJJMFueigz8TRfz8nwua_J5GwWt2t1dVcbHJLgszgCNBzGYeIjIbz&x-client-SKU=ID_NET8_0&x-client-ver=7.5.0.0 Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8BOu3dpzBwFIvsN1-x_vcjHq4VeweNeSsHYdS4PpY9QzMsAhXROlktny8-2xz-KpADHynEg8bd4GCgl_480VpzYCMlkEb46t5U9SaVUxPnMc70vjg1ZfUrnePKKob0ehCJlc6x9OUIInCWbXjvQ-p5vzqptOXw1vgBQ1xaY9Zg6n0yXbW0Q1Ey7upfvuVDvbxsoVWRF_268oiz57RmkM3zNs4mWGDBJRwVdd7aOaxCeTLW7fcA9reydi89wAVPN4vsbzS1SkUldBJj1qV90P8wc=N; expires=Fri, 23 Jan 2026 06:44:42 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: .AspNetCore.Correlation.AOUMWD7p2HxnOf6R_IJYBXH_jYOfIBEUOeodIOb4naE=N; expires=Sat, 24 Jan 2026 05:44:42 GMT; path=/signin-oidc; secure; samesite=none; httponly Strict-Transport-Security: max-age=31536000; includeSubDomains Request-Context: appId=cid-v1:e36f03f4-70ac-44c8-9618-1e4c289d94be x-azure-ref: 20260123T054442Z-17bcc8785fcgbh6zhC1FRAd0f40000001h70000000007y5m X-Cache: CONFIG_NOCACHE
Open service 13.107.213.60:443 · release-sessiondataaccessrules.trackmansoftball.com
2026-01-10 01:53
HTTP/1.1 302 Found Date: Sat, 10 Jan 2026 01:53:51 GMT Content-Length: 0 Connection: close Location: https://release-login.trackman.com/connect/authorize?client_id=SoftballSessionDataAccessRules&redirect_uri=https%3A%2F%2Frelease-sessiondataaccessrules.trackmansoftball.com%2Fsignin-oidc&response_type=code&scope=openid%20offline_access%20domain%3ASBSDAR%20permissions&code_challenge=fQsUviWWqEb38EUVxp0kGy11VSb-2PlOMEEvQJo6tAg&code_challenge_method=S256&response_mode=form_post&nonce=639036068313115499.YzMyMjVlN2YtN2ZiZS00ZThlLWExZTAtYmE5MDM0MTJmMWI2Y2JlZjFiZDgtZTllOS00OTc1LWE0OGYtZTYzMTZiZTRkZDBm&state=CfDJ8BOu3dpzBwFIvsN1-x_vcjF2L4NFrXl47wx_ig336_Kmle_KVVEtbZuTemm5_BolHv-W0huHPa9xDdRPKU2Bb7uo4H7MkOpo0BEFQk1VeEVysYJYCAEnwHdmVLj1-QlA8zq3Z6-2SjxK8Yky9L-ex5y6j4LZ95ueqel-vDteM1vEWWExZFkoH0yMvc4B0V-guONtm4pkWJlAvZqG6ArzDZdrqeVXOMTxw-DhRiugHgxGtYLzjLc4KVHAogyBBDGPp82qZTzDNu9uid7TdfDQuuDiNTocDUg9lqJU9aCrZOrsD9JCFtqafkaspRszPrwa2fZQx_g26vMUB0KwEsAdRpsQ9kNH1Bx87kTONLENchrHTeSpOIFiyyoO98JvXLSAc-ewK25U4HZo6fQ1gNjSCDitH2OnekwHBVqjw9LmB6yQ&x-client-SKU=ID_NET8_0&x-client-ver=7.5.0.0 Set-Cookie: .AspNetCore.OpenIdConnect.Nonce.CfDJ8BOu3dpzBwFIvsN1-x_vcjFZ5LrSCr4lKh-tPdx5YcEcYZIEFFaV-3I9D2GT9v1JK6wA--49mPYa8v1x-g4JXclPDKGNu95_iNExNv4-4kmbUhEv9TYAKqPzi4df-F2ekv5XTGW7PjekRXOttQJSeElmNk7JdlAj3jcOoGAUo7yfrQZFXm_fLSBXr2TKZ9O9b4ovOtPNQcRIOGwJrKp5v5NyGEMAg3E9H0hO3SFumoda5TESqwod7XEqTJlJYP0nOg-ObdQeCKYs6B65uN6LLPw=N; expires=Sat, 10 Jan 2026 02:53:51 GMT; path=/signin-oidc; secure; samesite=none; httponly Set-Cookie: .AspNetCore.Correlation.XwlkrASZz8OBCG9zY_9EF65_5mzqB6FmOQd8ENdmHXg=N; expires=Sun, 11 Jan 2026 01:53:51 GMT; path=/signin-oidc; secure; samesite=none; httponly Strict-Transport-Security: max-age=31536000; includeSubDomains Request-Context: appId=cid-v1:e36f03f4-70ac-44c8-9618-1e4c289d94be x-azure-ref: 20260110T015350Z-155869f5c8b9fgf9hC1AMSwcnw0000000fvg000000008f5b X-Cache: CONFIG_NOCACHE