Heroku
tcp/443
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 52.223.53.203:443 · www.bvalue.it
2026-01-09 18:51
HTTP/1.1 302 Found
Content-Language: it
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Fri, 09 Jan 2026 18:52:02 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=h1ZBRtr%2F2ZrmmjZ%2FEA5B41%2FYlsLeQXDwDlDiQDlu8Ao%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767984722"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=h1ZBRtr%2F2ZrmmjZ%2FEA5B41%2FYlsLeQXDwDlDiQDlu8Ao%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767984722"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /login
Open service 52.223.53.203:443 · www.bvalue.it
2026-01-02 19:17
HTTP/1.1 302 Found
Content-Language: it
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Fri, 02 Jan 2026 19:17:11 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=2mHZVrWaULCTU4i%2Bicx2PfkE5XeGO7fqaGMe%2BjBBmLc%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1767381431"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=2mHZVrWaULCTU4i%2Bicx2PfkE5XeGO7fqaGMe%2BjBBmLc%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1767381431"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /login
Open service 52.223.53.203:443 · www.bvalue.it
2025-12-22 22:01
HTTP/1.1 302 Found
Content-Language: it
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Mon, 22 Dec 2025 22:01:00 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=Iz4bA%2BaNVyOv%2FbinN05JjsCKr6i9x3qPG2AkXJCN0X8%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766440860"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=Iz4bA%2BaNVyOv%2FbinN05JjsCKr6i9x3qPG2AkXJCN0X8%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766440860"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /login
Open service 52.223.53.203:443 · www.bvalue.it
2025-12-21 04:12
HTTP/1.1 302 Found
Content-Language: it
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Sun, 21 Dec 2025 04:12:39 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=npeUIVKogjwsqjBXeMiozd58oJuzhmS2I91QAvo76fs%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766290359"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=npeUIVKogjwsqjBXeMiozd58oJuzhmS2I91QAvo76fs%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766290359"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /login
Open service 52.223.53.203:443 · www.bvalue.it
2025-12-19 02:04
HTTP/1.1 302 Found
Content-Language: it
Content-Length: 28
Content-Type: text/plain; charset=utf-8
Date: Fri, 19 Dec 2025 02:04:43 GMT
Location: /login
Nel: {"report_to":"heroku-nel","response_headers":["Via"],"max_age":3600,"success_fraction":0.01,"failure_fraction":0.1}
Report-To: {"group":"heroku-nel","endpoints":[{"url":"https://nel.heroku.com/reports?s=ujCTgTCqi1v%2Fvhn3aw4dt9C49g%2FkGyGYWHwbNQkRI1o%3D\u0026sid=812dcc77-0bd0-43b1-a5f1-b25750382959\u0026ts=1766109883"}],"max_age":3600}
Reporting-Endpoints: heroku-nel="https://nel.heroku.com/reports?s=ujCTgTCqi1v%2Fvhn3aw4dt9C49g%2FkGyGYWHwbNQkRI1o%3D&sid=812dcc77-0bd0-43b1-a5f1-b25750382959&ts=1766109883"
Server: Heroku
Vary: Accept, Accept-Encoding
Via: 1.1 heroku-router
X-Powered-By: Express
Connection: close
Found. Redirecting to /login