Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1926e27d0926e27d0926e27d0926e27d0926e27d0926e27d0
Public Swagger UI/API detected at path: /webjars/swagger-ui/index.html
Open service 2.18.64.85:443 · dev-tab-backend.choreograph.com
2026-01-23 06:45
HTTP/1.1 404 Not Found
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Content-Type: application/problem+json
Content-Length: 102
Expires: Fri, 23 Jan 2026 06:45:22 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 23 Jan 2026 06:45:22 GMT
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=428
Server-Timing: origin; dur=75
Server-Timing: ak_p; desc="1769150721726_34911125_49898927_50132_9303_143_258_-";dur=1
{"type":"about:blank","title":"Not Found","status":404,"detail":"No static resource .","instance":"/"}
Open service 2.18.64.85:443 · dev-tab-backend.choreograph.com
2026-01-10 01:55
HTTP/1.1 404 Not Found
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Content-Type: application/problem+json
Content-Length: 102
Expires: Sat, 10 Jan 2026 01:55:15 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 10 Jan 2026 01:55:15 GMT
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=81
Server-Timing: origin; dur=64
Server-Timing: ak_p; desc="1768010115782_34911109_323813193_14468_5006_0_5_-";dur=1
{"type":"about:blank","title":"Not Found","status":404,"detail":"No static resource .","instance":"/"}
Open service 2.18.64.85:80 · ingrammicro.fi
2026-01-07 08:32
HTTP/1.1 302 Moved Temporarily Location: https://ingrammicro.fi/ Expires: Wed, 07 Jan 2026 08:33:11 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Wed, 07 Jan 2026 08:33:11 GMT Connection: close Server-Timing: edge; dur=2 Server-Timing: origin; dur=2 Server-Timing: cdn-cache; desc=MISS Server-Timing: ak_p; desc="1767774791510_34911125_622595770_402_3580_152_0_-";dur=1
Open service 2.18.64.85:443 · ingrammicro.fi
2026-01-07 08:32
HTTP/1.1 301 Moved Permanently Content-Type: text/html; charset=utf-8 Location: https://fi.ingrammicro.eu X-Frame-Options: SAMEORIGIN X-ServerId: 6 Content-Security-Policy: frame-src *; frame-ancestors 'self' https://*.ingrammicro.com https://*.ingrammicro-asia.com https://*.ingrammicro.eu; Content-Length: 142 P3P: CP="CAO PSA OUR" Strict-Transport-Security: max-age=157680000; includeSubDomains; preload Expires: Wed, 07 Jan 2026 08:32:29 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Wed, 07 Jan 2026 08:32:29 GMT Connection: close Set-Cookie: CMSPreferredCulture=fi-FI; expires=Thu, 07-Jan-2027 08:32:29 GMT; path=/; secure; HttpOnly; SameSite=None Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=2 Server-Timing: origin; dur=15 Server-Timing: ak_p; desc="1767774749695_34911125_622553684_1722_4223_99_102_-";dur=1 Page title: Object moved <html><head><title>Object moved</title></head><body> <h2>Object moved to <a href="https://fi.ingrammicro.eu">here</a>.</h2> </body></html>
Open service 2.18.64.85:443 · www.cybersecuritycorporate.eu
2026-01-06 19:22
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 383 Expires: Tue, 06 Jan 2026 19:22:02 GMT Date: Tue, 06 Jan 2026 19:22:02 GMT Connection: close Strict-Transport-Security: max-age=86400 Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.cybersecuritycorporate.eu/" on this server.<P> Reference #18.95b31402.1767727322.20a6c671 <P>https://errors.edgesuite.net/18.95b31402.1767727322.20a6c671</P> </BODY> </HTML>
Open service 2.18.64.85:80 · www.cybersecuritycorporate.eu
2026-01-06 19:21
HTTP/1.1 403 Forbidden Mime-Version: 1.0 Content-Type: text/html Content-Length: 383 Expires: Tue, 06 Jan 2026 19:22:42 GMT Date: Tue, 06 Jan 2026 19:22:42 GMT Connection: close Page title: Access Denied <HTML><HEAD> <TITLE>Access Denied</TITLE> </HEAD><BODY> <H1>Access Denied</H1> You don't have permission to access "http://www.cybersecuritycorporate.eu/" on this server.<P> Reference #18.95b31402.1767727362.20abb4de <P>https://errors.edgesuite.net/18.95b31402.1767727362.20abb4de</P> </BODY> </HTML>
Open service 2.18.64.85:443 · tujijenge.or.tz
2026-01-06 18:20
HTTP/1.1 302 Moved Temporarily
Strict-Transport-Security: max-age=63072000; includeSubDomains
X-Frame-Options: SAMEORIGIN
X-Content-Type-Options: nosniff
Location: https://tujijenge.or.tz/en
Vary: Accept-Encoding
Content-Encoding: gzip
Content-Length: 197
Content-Type: text/html; charset=utf-8
Expires: Tue, 06 Jan 2026 18:20:22 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Tue, 06 Jan 2026 18:20:22 GMT
Connection: close
Set-Cookie: XSRF-TOKEN=eyJpdiI6InlvRjVaRVN2T3hpU1N4eklhQUtEUGc9PSIsInZhbHVlIjoiRjJEOXhsb0hEZjlqVzI4dDJ3V1RDOStDWjhZK2lxc2pqcUw2OXhQS2phOUtmMjYxTTRHSDI1OWE4K2tOMDdFVDB5T2QwQzNPZGZEWGIwRkdLTDFkVzB6NnM0TENZZTJ6eXE0MmdSQndSdWNNd2hHRytWTllka0FoV2ttWHhyWWEiLCJtYWMiOiIzZjFlZGY4MzJhNDU5M2RjMWE3Mjg1ZjBjNDdjN2VlYTY5YTA1ZTUyZTFhNTYxZjA3YWFlNjMwY2FlMGNhMTk5IiwidGFnIjoiIn0%3D; expires=Tue, 06 Jan 2026 20:20:22 GMT; Max-Age=7200; path=/; secure; samesite=lax
Set-Cookie: l_o_l_c_session=eyJpdiI6IndaMHQ5TmxCbDVqc25wdzJNZWY0c0E9PSIsInZhbHVlIjoiMkx1L1hLVkNVNEs1bVBmK3hlMC9PVnIyS0tTWVgvaDVScnkybFB4eU1Gc1ErR3VCT1ZtOW1NalRWVnp1VTRRaGFjaHA5YnpoaU1FSmtUYlVyb21XTGNyYjl5NTBaT1lBNTB2NFhJQ0srMytGY3ZCWE82cjA1NEhETWdoKzZPT28iLCJtYWMiOiJhMzU0NDg0N2YwMGY3MGUzMjhjYzVhN2Q1M2UwMGI2NDM1NjFmMzE2OWEzYjBjYjk0OTkwNTZhNjk3Yzk5NjM0IiwidGFnIjoiIn0%3D; expires=Tue, 06 Jan 2026 20:20:22 GMT; Max-Age=7200; path=/; secure; httponly; samesite=lax
Alt-Svc: h3=":443"; ma=93600
Akamai-Cache-Status: NotCacheable from child
Akamai-GRN: 0.95b31402.1767723622.1eed67e1
Akamai-GRN: 0.95b31402.1767723622.1eed67e1
Page title: Redirecting to https://tujijenge.or.tz/en
<!DOCTYPE html>
<html>
<head>
<meta charset="UTF-8" />
<meta http-equiv="refresh" content="0;url='https://tujijenge.or.tz/en'" />
<title>Redirecting to https://tujijenge.or.tz/en</title>
</head>
<body>
Redirecting to <a href="https://tujijenge.or.tz/en">https://tujijenge.or.tz/en</a>.
</body>
</html>
Open service 2.18.64.85:80 · tujijenge.or.tz
2026-01-06 18:20
HTTP/1.1 302 Moved Temporarily Content-Length: 0 Location: https://tujijenge.or.tz/ Expires: Tue, 06 Jan 2026 18:21:01 GMT Cache-Control: max-age=0, no-cache, no-store Pragma: no-cache Date: Tue, 06 Jan 2026 18:21:01 GMT Connection: close Akamai-Cache-Status: NotCacheable from child Akamai-GRN: 0.95b31402.1767723661.1ef230e5 Akamai-GRN: 0.95b31402.1767723661.1ef230e5
Open service 2.18.64.85:443 · dev-tab-backend.choreograph.com
2026-01-03 00:11
HTTP/1.1 404 Not Found
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Content-Type: application/problem+json
Content-Length: 102
Expires: Sat, 03 Jan 2026 00:11:59 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Sat, 03 Jan 2026 00:11:59 GMT
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=90
Server-Timing: origin; dur=69
Server-Timing: ak_p; desc="1767399119788_34911125_332542207_15882_5513_0_2_-";dur=1
{"type":"about:blank","title":"Not Found","status":404,"detail":"No static resource .","instance":"/"}
Open service 2.18.64.85:443 · dev-tab-backend.choreograph.com
2025-12-23 03:27
HTTP/1.1 404 Not Found
Vary: Origin
Vary: Access-Control-Request-Method
Vary: Access-Control-Request-Headers
Content-Type: application/problem+json
Content-Length: 102
Expires: Tue, 23 Dec 2025 03:27:29 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Tue, 23 Dec 2025 03:27:29 GMT
Connection: close
Server-Timing: cdn-cache; desc=MISS
Server-Timing: edge; dur=82
Server-Timing: origin; dur=63
Server-Timing: ak_p; desc="1766460449720_34911125_141559604_14460_4218_91_93_-";dur=1
{"type":"about:blank","title":"Not Found","status":404,"detail":"No static resource .","instance":"/"}