GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d74b2176f50
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] dashboard (args: none) : awardedLoans=0 approvedNotAwarded=0 simulations=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d7483cbb780
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf dashboard (args: none) : simulations=0 awardedLoans=0 approvedNotAwarded=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d74102a3e9c
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 dashboard (args: none) : simulations=0 awardedLoans=0 approvedNotAwarded=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d74267b682c
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf dashboard (args: none) : awardedLoans=0 approvedNotAwarded=0 simulations=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d74069979f4
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] dashboard (args: none) : simulations=0 awardedLoans=0 approvedNotAwarded=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d7442fb7aec
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 dashboard (args: none) : simulations=0 awardedLoans=0 approvedNotAwarded=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d749e8a1b74
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf dashboard (args: none) : approvedNotAwarded=0 simulations=0 awardedLoans=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d749f8907f0
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 dashboard (args: none) : simulations=0 awardedLoans=0 approvedNotAwarded=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d742502eaf8
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] dashboard (args: none) : approvedNotAwarded=0 simulations=0 awardedLoans=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d74a33245ce
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d747fae71e8
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 dashboard (args: none) : awardedLoans=0 approvedNotAwarded=0 simulations=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d74f2eeafd8
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 dashboard (args: none) : awardedLoans=0 approvedNotAwarded=0 simulations=0
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3546a889f8885eb2d8c09031f5a670d74936ccf10
GraphQL introspection enabled at /graphql Types: 49 (by kind: ENUM: 2, INPUT_OBJECT: 15, OBJECT: 27, SCALAR: 5) Operations: - Query: Query | fields: Simulation, dashboard, getConfig, getCoreParams, getCoreParamsLists - Mutation: Mutation | fields: getCheckList, saveSimulation, sendEmail, uploadDocuments Directives: deprecated, include, skip, specifiedBy (total: 4) Readable stores: 2 getConfig (args: none) : maxDownPaymentPercentage=93 maxDownPaymentPercentageSmart=50 allowedMimeTypes=[application/pdf image/jpeg image/png image/jpg] allowedFileTypes=.jpeg, .png, .jpg, .pdf maxFileSizeInKB=4e+07 dashboard (args: none) : approvedNotAwarded=0 simulations=0 awardedLoans=0
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Open service 142.250.185.211:443 · backend-amices.testing.amicar.com
2026-01-10 00:47
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: 636b81fba703fb2832ab31620965b32b
date: Sat, 10 Jan 2026 00:47:31 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.251.141.115:443 · backend-amices.testing.amicar.com
2026-01-09 13:54
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: f97b8fc714b73f4cc495b7e99ab30315
date: Fri, 09 Jan 2026 13:55:06 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.251.141.115:443 · backend-amices.testing.amicar.com
2026-01-02 19:16
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: d73caa78e7b719a65b058d130ad5382d
date: Fri, 02 Jan 2026 19:16:30 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.250.185.211:443 · backend-amices.testing.amicar.com
2026-01-02 14:56
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: f45e01b5bfae9645cc67125fd00db2cf
date: Fri, 02 Jan 2026 14:56:56 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.250.185.211:443 · backend-amices.testing.amicar.com
2025-12-23 09:00
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: 1fffc9f9fd34415611f123a9012c5562
date: Tue, 23 Dec 2025 09:00:38 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.251.141.115:443 · backend-amices.testing.amicar.com
2025-12-22 10:10
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: 1d443eb39719f0c494f912505245d32b
date: Mon, 22 Dec 2025 10:10:10 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.250.185.211:443 · backend-amices.testing.amicar.com
2025-12-21 06:11
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: f224d9b1c8134dcc11b107b1cf0d161f
date: Sun, 21 Dec 2025 06:11:46 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.250.185.211:443 · backend-amices.testing.amicar.com
2025-12-21 05:34
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: cb0d43513fb46a63f8353bbeea4bee02
date: Sun, 21 Dec 2025 05:34:46 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 2a00:1450:4001:807::2013:443 · backend-amices.testing.amicar.com
2025-12-20 19:26
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: da4d288352e55a8823feecc7c8da1137
date: Sat, 20 Dec 2025 19:27:03 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 2a00:1450:4001:807::2013:80 · backend-amices.testing.amicar.com
2025-12-20 19:26
HTTP/1.1 302 Found location: https://backend-amices.testing.amicar.com/ x-cloud-trace-context: fcb0796546133f41bcfb24d78b4a6495 date: Sat, 20 Dec 2025 19:26:55 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.251.141.115:443 · backend-amices.testing.amicar.com
2025-12-20 19:26
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: b3ce79266d9f6ce103fcaa275e5f3d07
date: Sat, 20 Dec 2025 19:27:03 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.251.141.115:80 · backend-amices.testing.amicar.com
2025-12-20 19:26
HTTP/1.1 302 Found location: https://backend-amices.testing.amicar.com/ x-cloud-trace-context: d8be2696404105e4ece503f8e633ad35 date: Sat, 20 Dec 2025 19:26:55 GMT content-type: text/html server: Google Frontend Content-Length: 0 Connection: close
Open service 142.250.185.211:443 · backend-amices.testing.amicar.com
2025-12-19 07:49
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: b2f69c6ac8aafa55ed673c55195b4230
date: Fri, 19 Dec 2025 07:49:56 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}
Open service 142.250.185.211:443 · backend-amices.testing.amicar.com
2025-12-19 02:27
HTTP/1.1 200 OK
x-dns-prefetch-control: off
x-frame-options: SAMEORIGIN
strict-transport-security: max-age=15552000; includeSubDomains
x-download-options: noopen
x-content-type-options: nosniff
x-xss-protection: 1; mode=block
access-control-allow-origin: *
content-type: application/json; charset=utf-8
etag: W/"1f-MNfUlGY8jMt82PHJ0T+4YdUjLyk"
x-cloud-trace-context: 6f6f1fdb9e230673222278a2fa62f834
date: Fri, 19 Dec 2025 02:27:45 GMT
server: Google Frontend
Content-Length: 31
Connection: close
{"message":"Welcome to AMICES"}