cloudflare
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd151e75e4b98651d5b19cca270eb6bf91a1ae9cabf38f46743
Public Swagger UI/API detected at path: /v3/api-docs - sample paths: GET /actuator GET /actuator/health GET /actuator/health/** GET /actuator/info GET /api/csv/template/download POST /api/data-extension/upload
Open service 104.18.36.178:443 · sfmc.mta.org
2026-01-10 00:24
HTTP/1.1 302 Found Date: Sat, 10 Jan 2026 00:24:49 GMT Content-Length: 0 Connection: close Server-Timing: cfCacheStatus;desc="MISS" Server-Timing: cfEdge;dur=59,cfOrigin;dur=39 Cache-Control: public, max-age=14400 expires: Sat, 10 Jan 2026 04:24:49 GMT Location: https://sfmc.mta.org/oauth2/authorization/marketing-cloud Pragma: no-cache Vary: Origin, accept-encoding Strict-Transport-Security: max-age=31536000 ; includeSubDomains X-Content-Type-Options: nosniff X-XSS-Protection: 0 Content-Security-Policy: frame-ancestors https://mc.s12.exacttarget.com/ cf-cache-status: MISS Set-Cookie: JSESSIONID=137DD263FFDD271DC753F9179136CF76; Path=/; Secure; HttpOnly; SameSite=None Set-Cookie: ARRAffinity=c2ea8bb4ab073da052d76c95a1829bf7bfeaf74efb6df29ac28f7717e950a4a3;Path=/;HttpOnly;Secure;Domain=sfmc.mta.org Set-Cookie: ARRAffinitySameSite=c2ea8bb4ab073da052d76c95a1829bf7bfeaf74efb6df29ac28f7717e950a4a3;Path=/;HttpOnly;SameSite=None;Secure;Domain=sfmc.mta.org set-cookie: __cf_bm=bZS0jyd5C7OrTgqnrEZ.B5nl5MpcwCzcWBLdA_c0LjQ-1768004689.0787692-1.0.1.1-ekasZYRHQr7bCx978xYNV_5fKy4ArK3fmkNvPfYc1kDOLXoBsQ357ga1iCbxykbgv711ELfYGMyAYVef6DsHd963tLp86RfJLbNeKXEoaGvINVFSdoOJcBjCxUberDA1; HttpOnly; Secure; Path=/; Domain=mta.org; Expires=Sat, 10 Jan 2026 00:54:49 GMT Server: cloudflare CF-RAY: 9bb8089ab8ec9444-SJC
Open service 104.18.36.178:443 · sfmc.mta.org
2026-01-02 20:23
HTTP/1.1 302 Found Date: Fri, 02 Jan 2026 20:23:15 GMT Content-Length: 0 Connection: close Server-Timing: cfCacheStatus;desc="MISS" Server-Timing: cfEdge;dur=13,cfOrigin;dur=97 Cache-Control: public, max-age=14400 expires: Sat, 03 Jan 2026 00:23:15 GMT Location: https://sfmc.mta.org/oauth2/authorization/marketing-cloud Pragma: no-cache Vary: Origin, accept-encoding Strict-Transport-Security: max-age=31536000 ; includeSubDomains X-Content-Type-Options: nosniff X-XSS-Protection: 0 Content-Security-Policy: frame-ancestors https://mc.s12.exacttarget.com/ cf-cache-status: MISS Set-Cookie: JSESSIONID=05A2E383D3DE6E66A1C22805EDB5E7AE; Path=/; Secure; HttpOnly; SameSite=None Set-Cookie: ARRAffinity=e7adbffe7a9306cf3b69e5759917ea1be4e8f496a9807afa71e7308ee38d5df3;Path=/;HttpOnly;Secure;Domain=sfmc.mta.org Set-Cookie: ARRAffinitySameSite=e7adbffe7a9306cf3b69e5759917ea1be4e8f496a9807afa71e7308ee38d5df3;Path=/;HttpOnly;SameSite=None;Secure;Domain=sfmc.mta.org set-cookie: __cf_bm=zJwugirK_W0Dh8IR3wXXApVm6Q3oRAtBqyOyR1au8D0-1767385395.8240972-1.0.1.1-2igyyP4cx6EroCOcvlc7Qzfyi0hmTR3vQxFq8R.pwdOsnSCNLjdl0Ft5lV11QFDhnCPT3CK.vOqfz3DN_Fjoqbwp9rCSHKUo0Si5NKLQ5ipblbhT3EYLtCDs66QmP7Wd; HttpOnly; Secure; Path=/; Domain=mta.org; Expires=Fri, 02 Jan 2026 20:53:15 GMT Server: cloudflare CF-RAY: 9b7cf923ef0b3616-FRA
Open service 104.18.36.178:443 · sfmc.mta.org
2025-12-23 03:01
HTTP/1.1 302 Found Date: Tue, 23 Dec 2025 03:01:10 GMT Content-Length: 0 Connection: close Server-Timing: cfCacheStatus;desc="MISS" Server-Timing: cfEdge;dur=19,cfOrigin;dur=92 Cache-Control: public, max-age=14400 expires: Tue, 23 Dec 2025 07:01:10 GMT Location: https://sfmc.mta.org/oauth2/authorization/marketing-cloud Pragma: no-cache Vary: Origin, accept-encoding Strict-Transport-Security: max-age=31536000 ; includeSubDomains X-Content-Type-Options: nosniff X-XSS-Protection: 0 Content-Security-Policy: frame-ancestors https://mc.s12.exacttarget.com/ cf-cache-status: MISS Set-Cookie: JSESSIONID=08B4E8033895BDFC3D057ADE4B1BF62F; Path=/; Secure; HttpOnly; SameSite=None Set-Cookie: ARRAffinity=c2ea8bb4ab073da052d76c95a1829bf7bfeaf74efb6df29ac28f7717e950a4a3;Path=/;HttpOnly;Secure;Domain=sfmc.mta.org Set-Cookie: ARRAffinitySameSite=c2ea8bb4ab073da052d76c95a1829bf7bfeaf74efb6df29ac28f7717e950a4a3;Path=/;HttpOnly;SameSite=None;Secure;Domain=sfmc.mta.org set-cookie: __cf_bm=AJIO8Yb_oMH5BW4ibt27WXnlZx.7nFoP2r8fEWhkMD0-1766458870.1635668-1.0.1.1-vMSvUOfq7H2Qd.clv08bcpDJLBAqoyTbynWOdtflkRYmWNvDyKxmu_jiZhruYRB3I8AjxXhl42Xtqms1EUWtEsEVMjQbJhIu6tq4KB6ok_6WAPsvh6FhPg9rwSpcHfFl; HttpOnly; Secure; Path=/; Domain=mta.org; Expires=Tue, 23 Dec 2025 03:31:10 GMT Server: cloudflare CF-RAY: 9b249ce28b3d06aa-LHR
Open service 104.18.36.178:443 · sfmc.mta.org
2025-12-21 08:00
HTTP/1.1 302 Found Date: Sun, 21 Dec 2025 08:00:22 GMT Content-Length: 0 Connection: close Server-Timing: cfCacheStatus;desc="MISS" Server-Timing: cfEdge;dur=38,cfOrigin;dur=38 Cache-Control: public, max-age=14400 expires: Sun, 21 Dec 2025 12:00:22 GMT Location: https://sfmc.mta.org/oauth2/authorization/marketing-cloud Pragma: no-cache Vary: Origin, accept-encoding Strict-Transport-Security: max-age=31536000 ; includeSubDomains X-Content-Type-Options: nosniff X-XSS-Protection: 0 Content-Security-Policy: frame-ancestors https://mc.s12.exacttarget.com/ cf-cache-status: MISS Set-Cookie: JSESSIONID=D307D2276F74ACBC9F89824D7924BDB1; Path=/; Secure; HttpOnly; SameSite=None Set-Cookie: ARRAffinity=c2ea8bb4ab073da052d76c95a1829bf7bfeaf74efb6df29ac28f7717e950a4a3;Path=/;HttpOnly;Secure;Domain=sfmc.mta.org Set-Cookie: ARRAffinitySameSite=c2ea8bb4ab073da052d76c95a1829bf7bfeaf74efb6df29ac28f7717e950a4a3;Path=/;HttpOnly;SameSite=None;Secure;Domain=sfmc.mta.org set-cookie: __cf_bm=T70sn1g5d546T5m2BIApswfAciN5GsgeA_HT15x0fMw-1766304022.2949235-1.0.1.1-uqrWOoC5YtGgv2XAVJ0Q7L888bs1uG7aM_IFIv.XvXpC6knZB3qe86plcZWOQ9y9AB4teaeAaL7_MjC3AgDyhqaer4Yj5qv9rW9qAhuwwXgvSAHq78Qnsn.xVRofZsyX; HttpOnly; Secure; Path=/; Domain=mta.org; Expires=Sun, 21 Dec 2025 08:30:22 GMT Server: cloudflare CF-RAY: 9b15d86b5e3cc477-EWR
Open service 104.18.36.178:443 · sfmc.mta.org
2025-12-19 09:19
HTTP/1.1 302 Found Date: Fri, 19 Dec 2025 09:19:04 GMT Content-Length: 0 Connection: close Server-Timing: cfCacheStatus;desc="MISS" Server-Timing: cfEdge;dur=22,cfOrigin;dur=92 Cache-Control: public, max-age=14400 expires: Fri, 19 Dec 2025 13:19:04 GMT Location: https://sfmc.mta.org/oauth2/authorization/marketing-cloud Pragma: no-cache Vary: Origin, accept-encoding Strict-Transport-Security: max-age=31536000 ; includeSubDomains X-Content-Type-Options: nosniff X-XSS-Protection: 0 Content-Security-Policy: frame-ancestors https://mc.s12.exacttarget.com/ cf-cache-status: MISS Set-Cookie: JSESSIONID=6453549E5BDD976C5E111B1A0894FC4B; Path=/; Secure; HttpOnly; SameSite=None Set-Cookie: ARRAffinity=b4883d318cebb18b2d2d0cd3d793f8be5988d263c96fc4010f1588f09f2700b2;Path=/;HttpOnly;Secure;Domain=sfmc.mta.org Set-Cookie: ARRAffinitySameSite=b4883d318cebb18b2d2d0cd3d793f8be5988d263c96fc4010f1588f09f2700b2;Path=/;HttpOnly;SameSite=None;Secure;Domain=sfmc.mta.org set-cookie: __cf_bm=PD49ZHetMw1bKvCnckvdaa0R0uSIQCS9DHXE32d98zw-1766135944.2066636-1.0.1.1-pzPSj6yfdxrM_Cl8FY7iJxhN4RZ3QzpuUmEEqKK2flcRUfM_V.EJxGprk1P8o8qTGUXy3.409vfTrPKRpDy8cid1vBz8uF7vtW0M_UxDQWtQR9JzIj531obs5Fj_.xRw; HttpOnly; Secure; Path=/; Domain=mta.org; Expires=Fri, 19 Dec 2025 09:49:04 GMT Server: cloudflare CF-RAY: 9b05d0f34f6076f9-LHR