Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Open service 13.107.246.69:80 · user.test2.icondigitalplatform.dev
2026-01-10 09:00
HTTP/1.1 307 Temporary Redirect Date: Sat, 10 Jan 2026 09:00:09 GMT Content-Type: text/html Content-Length: 0 Connection: close Location: https://user.test2.icondigitalplatform.dev/ x-azure-ref: 20260110T090009Z-r17955489d56v56rhC1FRA8dq40000000cd000000000kab0 X-Cache: CONFIG_NOCACHE
Open service 13.107.213.44:443 · user.test2.icondigitalplatform.dev
2026-01-08 23:28
HTTP/1.1 404 Not Found Date: Thu, 08 Jan 2026 23:28:38 GMT Content-Length: 0 Connection: close Cache-Control: no-store Pragma: no-cache Strict-Transport-Security: max-age=31536000; includeSubDomains; preload x-ms-middleware-request-id: 00000000-0000-0000-0000-000000000000 X-Trace-Id: 215ac6779faf594106bb201844401f07 x-azure-ref: 20260108T232838Z-169bcb8b8b8j677mhC1ATLs9tg00000006eg00000000556p X-Cache: CONFIG_NOCACHE set-cookie: ASLBSA=0003e283eecdc1d4f7a89ec3671d7d7b9acbcc3e6d3c65e49fce63bced2337f06481; Path=/; Secure; HttpOnly; set-cookie: ASLBSACORS=0003e283eecdc1d4f7a89ec3671d7d7b9acbcc3e6d3c65e49fce63bced2337f06481; SameSite=none; Path=/; Secure; HttpOnly;
Open service 13.107.213.44:443 · user.test2.icondigitalplatform.dev
2026-01-01 22:07
HTTP/1.1 404 Not Found Date: Thu, 01 Jan 2026 22:07:22 GMT Content-Length: 0 Connection: close Cache-Control: no-store Pragma: no-cache Strict-Transport-Security: max-age=31536000; includeSubDomains; preload x-ms-middleware-request-id: 00000000-0000-0000-0000-000000000000 X-Trace-Id: 7170b94d5281ba571e8b0168aef028b0 x-azure-ref: 20260101T220721Z-185d974d666hlrbvhC1FRAc95g0000002ky000000000a0e6 X-Cache: CONFIG_NOCACHE set-cookie: ASLBSA=0003e283eecdc1d4f7a89ec3671d7d7b9acbcc3e6d3c65e49fce63bced2337f06481; Path=/; Secure; HttpOnly; set-cookie: ASLBSACORS=0003e283eecdc1d4f7a89ec3671d7d7b9acbcc3e6d3c65e49fce63bced2337f06481; SameSite=none; Path=/; Secure; HttpOnly;
Open service 13.107.213.44:443 · user.test2.icondigitalplatform.dev
2025-12-22 18:48
HTTP/1.1 404 Not Found Date: Mon, 22 Dec 2025 18:48:54 GMT Content-Length: 0 Connection: close Cache-Control: no-store Pragma: no-cache Strict-Transport-Security: max-age=31536000; includeSubDomains; preload x-ms-middleware-request-id: 00000000-0000-0000-0000-000000000000 X-Trace-Id: 1d07ed315319abd732eef8b85f6aabc8 x-azure-ref: 20251222T184854Z-185d974d666xch75hC1FRAmt6n0000000r8000000000831b X-Cache: CONFIG_NOCACHE set-cookie: ASLBSA=0003e283eecdc1d4f7a89ec3671d7d7b9acbcc3e6d3c65e49fce63bced2337f06481; Path=/; Secure; HttpOnly; set-cookie: ASLBSACORS=0003e283eecdc1d4f7a89ec3671d7d7b9acbcc3e6d3c65e49fce63bced2337f06481; SameSite=none; Path=/; Secure; HttpOnly;