Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549d878b032b2346c5c8ae1a1fcb39135515162a9a4
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /v1/cache/access/automation/{automationId}/{actionId}
GET /v1/cache/access/{applicationId}/{dataflowId}
GET /v1/cache/blacklisted-domains
GET /v1/cache/code-snippet/{codeSnippetId}
GET /v1/cache/tenant-settings/{orgShortCode}
GET /v1/cache/transaction-logs-mappings/{dataflowId}
GET /v1/cache/{applicationId}
GET /v1/cache/{applicationId}/{dataflowId}
GET /v1/status/{requestId}
GET /v1/webhook/lsq/{orgShortCode}/{providerId}/{connectorId}/{applicationId}/{dataflowId}
POST /v1/automation/{orgShortCode}/{providerId}/{connectorId}
POST /v1/cache/globalVariable/{applicationId}/{globalVariableId}
POST /v1/code-executor
POST /v1/decrypt/icKey/{orgShortCode}/{providerId}/{connectorId}
POST /v1/hl7/parse
POST /v1/retry/lsq/{orgShortCode}/{providerId}/{connectorId}/{applicationId}/{dataflowId}
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549d878b032b2346c5c8ae1a1fcb39135515ffac1e8
Public Swagger UI/API detected at path: /swagger/index.html - sample paths:
GET /v1/cache/access/automation/{automationId}/{actionId}
GET /v1/cache/access/{applicationId}/{dataflowId}
GET /v1/cache/blacklisted-domains
GET /v1/cache/code-snippet/{codeSnippetId}
GET /v1/cache/tenant-settings/{orgShortCode}
GET /v1/cache/transaction-logs-mappings/{dataflowId}
GET /v1/cache/{applicationId}
GET /v1/cache/{applicationId}/{dataflowId}
GET /v1/status/{requestId}
GET /v1/webhook/lsq/{orgShortCode}/{providerId}/{connectorId}/{applicationId}/{dataflowId}
POST /v1/automation/{orgShortCode}/{providerId}/{connectorId}
POST /v1/cache/globalVariable/{applicationId}/{globalVariableId}
POST /v1/code-executor
POST /v1/decrypt/icKey/{orgShortCode}/{providerId}/{connectorId}
POST /v1/retry/lsq/{orgShortCode}/{providerId}/{connectorId}/{applicationId}/{dataflowId}
Open service 23.50.131.157:443 · poonawalla-uat-integrationcloud.leadsquaredapps.com
2026-01-23 08:28
HTTP/1.1 404 Not Found Content-Length: 0 Cache-Control: max-age=0 Date: Fri, 23 Jan 2026 08:28:45 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=144 Server-Timing: origin; dur=4 Alt-Svc: h3=":443"; ma=93600 Akamai-GRN: 0.1d173317.1769156925.25d3e3e8 Server-Timing: ak_p; desc="1769156924965_389224221_634643432_14803_4091_93_192_-";dur=1
Open service 23.50.131.157:443 · poonawalla-uat-integrationcloud.leadsquaredapps.com
2026-01-09 11:57
HTTP/1.1 404 Not Found Content-Length: 0 Cache-Control: max-age=0 Date: Fri, 09 Jan 2026 11:57:24 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=416 Server-Timing: origin; dur=39 Alt-Svc: h3=":443"; ma=93600 Akamai-GRN: 0.1d173317.1767959843.c1d5b5bd Server-Timing: ak_p; desc="1767959843567_389224221_3252008381_45401_10222_0_167_-";dur=1
Open service 23.50.131.157:443 · poonawalla-uat-integrationcloud.leadsquaredapps.com
2026-01-02 20:48
HTTP/1.1 404 Not Found Content-Length: 0 Cache-Control: max-age=0 Date: Fri, 02 Jan 2026 20:49:00 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=129 Server-Timing: origin; dur=4 Alt-Svc: h3=":443"; ma=93600 Akamai-GRN: 0.10173317.1767386940.8fd829ec Server-Timing: ak_p; desc="1767386940029_389224208_2413308396_13262_5274_1_4_-";dur=1
Open service 23.50.131.157:443 · poonawalla-uat-integrationcloud.leadsquaredapps.com
2025-12-23 00:01
HTTP/1.1 404 Not Found Content-Length: 0 Cache-Control: max-age=0 Date: Tue, 23 Dec 2025 00:01:37 GMT Connection: close Server-Timing: cdn-cache; desc=MISS Server-Timing: edge; dur=146 Server-Timing: origin; dur=6 Alt-Svc: h3=":443"; ma=93600 Akamai-GRN: 0.1d173317.1766448097.49e51e60 Server-Timing: ak_p; desc="1766448097251_389224221_1239752288_15187_4391_149_300_-";dur=1