Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549e0acb8ad1191e6ffce3c593f36b0c2648bd30909
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: GET /api/v1/request-quote/equipment-sizes GET /api/v1/request-quote/services-status POST /api/v1/request-quote POST /api/v1/request-quote/send-mail POST /api/v1/request-quote/send-mail-mocked
Open service 2.16.1.234:443 · quote-request-be.mymsc.com
2026-01-22 11:54
HTTP/1.1 200 OK
Content-Type: application/json
Expires: Thu, 22 Jan 2026 11:54:21 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Thu, 22 Jan 2026 11:54:21 GMT
Content-Length: 162
Connection: close
Set-Cookie: ARRAffinity=04cd653d8eaa137294fe8c0cc7d9dfc577f9e32452b8c7b4a9a0627f5007768a;Path=/;HttpOnly;Secure;Domain=quote-request-be.mymsc.com
Set-Cookie: ARRAffinitySameSite=04cd653d8eaa137294fe8c0cc7d9dfc577f9e32452b8c7b4a9a0627f5007768a;Path=/;HttpOnly;SameSite=None;Secure;Domain=quote-request-be.mymsc.com
Server-Timing: edge; dur=1
Server-Timing: origin; dur=15
Server-Timing: cdn-cache; desc=MISS
Server-Timing: ak_p; desc="1769082861762_34603413_264868233_1597_8092_0_4_-";dur=1
{
"version": "1.0.0.0",
"statusCode": 200,
"message": "GET Request successful.",
"result": {
"message": "Request Quote Form Backend API!"
}
}
Open service 2.16.1.234:443 · quote-request-be.mymsc.com
2026-01-09 14:30
HTTP/1.1 200 OK
Content-Type: application/json
Expires: Fri, 09 Jan 2026 14:31:01 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 09 Jan 2026 14:31:01 GMT
Content-Length: 162
Connection: close
Set-Cookie: ARRAffinity=3fd8de456c99c884b0950144b7431b1c0dd0c52d947730e29d6132fb48aaa899;Path=/;HttpOnly;Secure;Domain=quote-request-be.mymsc.com
Set-Cookie: ARRAffinitySameSite=3fd8de456c99c884b0950144b7431b1c0dd0c52d947730e29d6132fb48aaa899;Path=/;HttpOnly;SameSite=None;Secure;Domain=quote-request-be.mymsc.com
Server-Timing: edge; dur=1
Server-Timing: origin; dur=16
Server-Timing: cdn-cache; desc=MISS
Server-Timing: ak_p; desc="1767969061203_34603399_1057881313_1676_8052_83_87_-";dur=1
{
"version": "1.0.0.0",
"statusCode": 200,
"message": "GET Request successful.",
"result": {
"message": "Request Quote Form Backend API!"
}
}
Open service 2.16.1.234:443 · quote-request-be.mymsc.com
2026-01-02 18:56
HTTP/1.1 200 OK
Content-Type: application/json
Expires: Fri, 02 Jan 2026 18:56:26 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Fri, 02 Jan 2026 18:56:26 GMT
Content-Length: 162
Connection: close
Set-Cookie: ARRAffinity=88818588a46aa3458c965104c74df2f6ea93608131cce5309c470e7127f7ae9f;Path=/;HttpOnly;Secure;Domain=quote-request-be.mymsc.com
Set-Cookie: ARRAffinitySameSite=88818588a46aa3458c965104c74df2f6ea93608131cce5309c470e7127f7ae9f;Path=/;HttpOnly;SameSite=None;Secure;Domain=quote-request-be.mymsc.com
Server-Timing: edge; dur=14
Server-Timing: origin; dur=49
Server-Timing: cdn-cache; desc=MISS
Server-Timing: ak_p; desc="1767380185820_34603399_774125659_6225_18707_183_218_-";dur=1
{
"version": "1.0.0.0",
"statusCode": 200,
"message": "GET Request successful.",
"result": {
"message": "Request Quote Form Backend API!"
}
}
Open service 2.16.1.234:443 · quote-request-be.mymsc.com
2025-12-23 08:15
HTTP/1.1 200 OK
Content-Type: application/json
Expires: Tue, 23 Dec 2025 08:15:57 GMT
Cache-Control: max-age=0, no-cache, no-store
Pragma: no-cache
Date: Tue, 23 Dec 2025 08:15:57 GMT
Content-Length: 162
Connection: close
Set-Cookie: ARRAffinity=f338cc84dcd26ef0541e10991beb3f601c2d1a0e9ced27dcfbc2140d4a6a8e25;Path=/;HttpOnly;Secure;Domain=quote-request-be.mymsc.com
Set-Cookie: ARRAffinitySameSite=f338cc84dcd26ef0541e10991beb3f601c2d1a0e9ced27dcfbc2140d4a6a8e25;Path=/;HttpOnly;SameSite=None;Secure;Domain=quote-request-be.mymsc.com
Server-Timing: edge; dur=2
Server-Timing: origin; dur=14
Server-Timing: cdn-cache; desc=MISS
Server-Timing: ak_p; desc="1766477757382_34603399_338459765_1545_8100_0_3_-";dur=1
{
"version": "1.0.0.0",
"statusCode": 200,
"message": "GET Request successful.",
"result": {
"message": "Request Quote Form Backend API!"
}
}