Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549f4e01e5fd3d3cbf740b213b9c3c7c073d292f85b
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /api/dsgapi/login
GET /service/Health/ping
GET /service/Settings
GET /service/Settings/{section}
GET /service/Settings/{section}/{key}
POST /api/dsgapi/dsgapplicationconfig
POST /api/dsgapi/dsgbackupsastoken
POST /api/dsgapi/dsgdataproviderconfig
POST /api/dsgapi/dsgdeleteddataproviderlist
POST /api/dsgapi/dsgloggingconfig
POST /api/dsgapi/dsgrestoresastoken
POST /api/dsgapi/dsgstate
POST /api/dsgapi/eventacknowledgement
POST /api/dsgapi/eventfailure
POST /api/dsgapi/events
POST /api/dsgapi/hearbeats
POST /api/dsgapi/indexitems
POST /api/dsgapi/investigateapplicationconfig
POST /api/dsgapi/investigatedataproviderconfig
POST /api/dsgapi/investigatedataproviderlist
POST /api/dsgapi/investigateloggingconfig
POST /api/dsgapi/logevents
POST /api/dsgapi/pendingretrievals
POST /api/dsgapi/prpstatistics
POST /api/dsgapi/replay
POST /api/dsgapi/retrievalfiles
POST /api/dsgapi/retrievals
POST /api/dsgapi/users
Open service 20.105.216.40:443 · maharastrapd-dsgapi.nidemo.com
2026-01-23 00:03
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 23 Jan 2026 00:04:01 GMT Cache-Control: no-store, no-cache Request-Context: appId=cid-v1:02966725-0b0d-4a2b-a9f9-05c8e486f78e X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: NOSNIFF Referrer-Policy: no-referrer-when-downgrade Feature-Policy: speaker 'none'; geolocation 'none'; microphone 'none'; autoplay 'none'; camera 'none'
Open service 20.105.216.40:443 · maharastrapd-dsgapi.nidemo.com
2026-01-09 10:41
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Fri, 09 Jan 2026 10:42:10 GMT Cache-Control: no-store, no-cache Request-Context: appId=cid-v1:02966725-0b0d-4a2b-a9f9-05c8e486f78e X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: NOSNIFF Referrer-Policy: no-referrer-when-downgrade Feature-Policy: speaker 'none'; geolocation 'none'; microphone 'none'; autoplay 'none'; camera 'none'
Open service 20.105.216.40:443 · maharastrapd-dsgapi.nidemo.com
2026-01-06 16:31
HTTP/1.1 404 Not Found Content-Length: 0 Connection: close Date: Tue, 06 Jan 2026 16:32:30 GMT Cache-Control: no-store, no-cache Request-Context: appId=cid-v1:02966725-0b0d-4a2b-a9f9-05c8e486f78e X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block X-Content-Type-Options: NOSNIFF Referrer-Policy: no-referrer-when-downgrade Feature-Policy: speaker 'none'; geolocation 'none'; microphone 'none'; autoplay 'none'; camera 'none'
Open service 20.105.216.40:80 · maharastrapd-dsgapi.nidemo.com
2026-01-06 16:31
HTTP/1.1 301 Moved Permanently Content-Length: 0 Connection: close Date: Tue, 06 Jan 2026 16:32:31 GMT Location: https://maharastrapd-dsgapi.nidemo.com/