Kestrel
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549152bc76d548d989a6caf14606cf4a0a8d5767a0d
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /DownloadRawImage/{id}
GET /ReportImages/{id}
GET /TemperatureExport/{id}/{step}
GET /api/Clinic
GET /api/Profile
GET /api/ScanImage
POST /api/Auth
POST /api/ScanImageRawMultiple
POST /api/ScanImageRawSingle
POST /api/ScanImagev1
POST /api/ScanSession
POST /api/SessionStatus
Open service 20.90.134.13:443 · thermocheck.codeg.uy
2026-01-22 19:46
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Thu, 22 Jan 2026 19:47:18 GMT Server: Kestrel Location: https://thermocheck.codeg.uy/Account/LogIn?ReturnUrl=%2F Request-Context: appId=cid-v1:2ca87016-bf53-439a-9a27-0bf2d2f54216
Open service 20.90.134.13:80 · thermocheck.codeg.uy
2026-01-12 03:28
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Mon, 12 Jan 2026 03:29:04 GMT Location: https://thermocheck.codeg.uy/
Open service 20.90.134.13:443 · thermocheck.codeg.uy
2026-01-12 03:28
HTTP/1.1 302 Found Content-Length: 0 Connection: close Date: Mon, 12 Jan 2026 03:29:03 GMT Server: Kestrel Location: https://thermocheck.codeg.uy/Account/LogIn?ReturnUrl=%2F Request-Context: appId=cid-v1:2ca87016-bf53-439a-9a27-0bf2d2f54216