Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c43da80144bacdc3761910b95f8cb1f9baf22eca
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /Private/AccountDelete GET /Private/AccountChangeStatus GET /Private/CompaniesLanguage GET /Private/CompanyList GET /Private/CountryGetList GET /Private/EmployeeSendActivationEmail GET /Private/GetAkamaiToken GET /Private/GetHangfireJobs GET /Private/GetListCompanyType GET /Private/GetProfile GET /Private/GetUserActiveList GET /Private/GetUserFromId GET /Private/InviteGetInfo GET /Private/LanguageGetListFromOfficeId GET /Private/ResentInvitation GET /Private/StartRemainderExpiredEmployee GET /Private/UserGetInfoLogIn GET /Private/UserRoleAccountManagementGetInfo GET /Private/rescheduleAllHangfiresJobs GET /Public/AdminProvider_Get GET /Public/CheckGUID GET /Public/CompanyGet GET /Public/EmployeeActiveAccount GET /Public/EndSession GET /Public/ErrorAuthorized GET /Public/GetCurrencyCode GET /Public/GetDropdownLangVisible GET /Public/GetLabel GET /Public/GetLabelKey_ForDropDown GET /Public/GetMSCBookingLink GET /Public/GetPages_ForDropDown GET /Public/GetTranslationFile GET /Public/SearchTranslationLabels GET /Public/Test POST /Private/AdminInvitation POST /Private/CheckUserPartnerPortal POST /Private/CompanyInsert POST /Private/CompanyUpdate POST /Private/EmployeeAccountUpdate POST /Private/InsertOrUpdateProfile POST /Private/SendGenericEmail POST /Private/UserRoleAccountUpdate POST /Private/searchEmployeeAccount POST /Private/searchUserRoleAccount POST /Public/PreRegistrationEmployee POST /Public/UpdateLabel
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c43da80144bacdc3761910b95f8cb1f949d1f3e3
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /Private/AccountDelete GET /Private/AccountChangeStatus GET /Private/CompaniesLanguage GET /Private/CompanyList GET /Private/EmployeeSendActivationEmail GET /Private/GetAkamaiToken GET /Private/GetHangfireJobs GET /Private/GetListCompanyType GET /Private/GetProfile GET /Private/GetUserActiveList GET /Private/GetUserFromId GET /Private/InviteGetInfo GET /Private/LanguageGetListFromOfficeId GET /Private/ResentInvitation GET /Private/StartRemainderExpiredEmployee GET /Private/UserGetInfoLogIn GET /Private/UserRoleAccountManagementGetInfo GET /Private/rescheduleAllHangfiresJobs GET /Public/AdminProvider_Get GET /Public/CheckGUID GET /Public/CompanyGet GET /Public/EmployeeActiveAccount GET /Public/EndSession GET /Public/ErrorAuthorized GET /Public/GetCurrencyCode GET /Public/GetDropdownLangVisible GET /Public/GetLabel GET /Public/GetLabelKey_ForDropDown GET /Public/GetMSCBookingLink GET /Public/GetPages_ForDropDown GET /Public/GetTranslationFile GET /Public/SearchTranslationLabels GET /Public/Test POST /Private/AdminInvitation POST /Private/CheckUserPartnerPortal POST /Private/CompanyInsert POST /Private/CompanyUpdate POST /Private/EmployeeAccountUpdate POST /Private/InsertOrUpdateProfile POST /Private/SendGenericEmail POST /Private/UserRoleAccountUpdate POST /Private/searchEmployeeAccount POST /Private/searchUserRoleAccount POST /Public/PreRegistrationEmployee POST /Public/UpdateLabel
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c43da80144bacdc3761910b95f8cb1f9a9421ed1
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /Private/AccountDelete GET /Private/AccountChangeStatus GET /Private/CompaniesLanguage GET /Private/CompanyList GET /Private/EmployeeSendActivationEmail GET /Private/GetAkamaiToken GET /Private/GetHangfireJobs GET /Private/GetListCompanyType GET /Private/GetProfile GET /Private/GetUserActiveList GET /Private/GetUserFromId GET /Private/InviteGetInfo GET /Private/LanguageGetListFromOfficeId GET /Private/ResentInvitation GET /Private/StartRemainderExpiredEmployee GET /Private/UserGetInfoLogIn GET /Private/UserRoleAccountManagementGetInfo GET /Private/rescheduleAllHangfiresJobs GET /Public/CheckGUID GET /Public/CompanyGet GET /Public/EmployeeActiveAccount GET /Public/EndSession GET /Public/ErrorAuthorized GET /Public/GetCurrencyCode GET /Public/GetDropdownLangVisible GET /Public/GetLabel GET /Public/GetLabelKey_ForDropDown GET /Public/GetMSCBookingLink GET /Public/GetPages_ForDropDown GET /Public/GetTranslationFile GET /Public/SearchTranslationLabels GET /Public/Test GET /Public/TestAzure POST /Private/AdminInvitation POST /Private/CheckUserPartnerPortal POST /Private/CompanyInsert POST /Private/CompanyUpdate POST /Private/EmployeeAccountUpdate POST /Private/InsertOrUpdateProfile POST /Private/SendGenericEmail POST /Private/UserRoleAccountUpdate POST /Private/searchEmployeeAccount POST /Private/searchUserRoleAccount POST /Public/PreRegistrationEmployee POST /Public/UpdateLabel
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c43da80144bacdc3761910b95f8cb1f9ea0ca734
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /Private/AccountDelete GET /Private/AccountChangeStatus GET /Private/CompaniesLanguage GET /Private/CompanyList GET /Private/EmployeeSendActivationEmail GET /Private/GetAkamaiToken GET /Private/GetHangfireJobs GET /Private/GetListCompanyType GET /Private/GetProfile GET /Private/GetUserActiveList GET /Private/GetUserFromId GET /Private/InviteGetInfo GET /Private/LanguageGetListFromOfficeId GET /Private/ReportCompany GET /Private/ReportCompanyByCountry GET /Private/ReportCompanyByCountryExcel GET /Private/ReportCountBookingForYear GET /Private/ReportCountBookingForYearExcel GET /Private/ReportRegisteredUser GET /Private/ReportRegisteredUserExcel GET /Private/ResentInvitation GET /Private/StartRemainderExpiredEmployee GET /Private/UserGetInfoLogIn GET /Private/UserRoleAccountManagementGetInfo GET /Private/rescheduleAllHangfiresJobs GET /Public/CheckGUID GET /Public/CompanyGet GET /Public/EmployeeActiveAccount GET /Public/EndSession GET /Public/ErrorAuthorized GET /Public/GetCurrencyCode GET /Public/GetDropdownLangVisible GET /Public/GetLabel GET /Public/GetLabelKey_ForDropDown GET /Public/GetMSCBookingLink GET /Public/GetPages_ForDropDown GET /Public/GetTranslationFile GET /Public/SearchTranslationLabels GET /Public/Test GET /Public/TestAzure POST /Private/AdminInvitation POST /Private/CheckUserPartnerPortal POST /Private/CompanyInsert POST /Private/CompanyUpdate POST /Private/ContactUs POST /Private/EmployeeAccountUpdate POST /Private/InsertOrUpdateProfile POST /Private/SendGenericEmail POST /Private/UserRoleAccountUpdate POST /Private/searchEmployeeAccount POST /Private/searchUserRoleAccount POST /Public/ContactUs POST /Public/PreRegistrationEmployee POST /Public/UpdateLabel
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c43da80118659b95776e449790a8ab0df9d5ab1c
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /Private/AccountDelete DELETE /Private/BookingDelete GET /Private/AccountChangeStatus GET /Private/CompaniesLanguage GET /Private/CompanyList GET /Private/EmployeeSendActivationEmail GET /Private/GetAkamaiToken GET /Private/GetListCompanyType GET /Private/GetProfile GET /Private/GetUserActiveList GET /Private/GetUserFromId GET /Private/InviteGetInfo GET /Private/LanguageGetListFromOfficeId GET /Private/ReportCompany GET /Private/ReportCompanyByCountry GET /Private/ReportCompanyByCountryExcel GET /Private/ReportCountBookingForYear GET /Private/ReportCountBookingForYearExcel GET /Private/ReportRegisteredUser GET /Private/ReportRegisteredUserExcel GET /Private/ResentInvitation GET /Private/UserGetInfoLogIn GET /Private/UserRoleAccountManagementGetInfo GET /Public/CheckGUID GET /Public/CompanyGet GET /Public/EmployeeActiveAccount GET /Public/EndSession GET /Public/Error GET /Public/GetCurrencyCode GET /Public/GetDropdownLangVisible GET /Public/GetLabel GET /Public/GetLabelKey_ForDropDown GET /Public/GetMSCBookingLink GET /Public/GetPages_ForDropDown GET /Public/GetTranslationFile GET /Public/SearchTranslationLabels GET /Public/Test POST /Private/AdminInvitation POST /Private/BookingAdd POST /Private/BookingSearch POST /Private/BookingUpdate POST /Private/CheckUserPartnerPortal POST /Private/CompanyInsert POST /Private/CompanyUpdate POST /Private/ContactUs POST /Private/EmployeeAccountUpdate POST /Private/InsertOrUpdateProfile POST /Private/SendGenericEmail POST /Private/UserRoleAccountUpdate POST /Private/searchEmployeeAccount POST /Private/searchUserRoleAccount POST /Public/ContactUs POST /Public/PreRegistrationEmployee POST /Public/UpdateLabel
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d603a99618638f913fc9250375e57e0e0bc09b71893
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths: DELETE /Private/AccountDelete DELETE /Private/BookingDelete GET /Private/AccountChangeStatus GET /Private/CompaniesLanguage GET /Private/CompanyList GET /Private/EmployeeSendActivationEmail GET /Private/GetAkamaiToken GET /Private/GetListCompanyType GET /Private/GetProfile GET /Private/GetUserActiveList GET /Private/GetUserFromId GET /Private/InviteGetInfo GET /Private/LanguageGetListFromOfficeId GET /Private/ReportCompany GET /Private/ReportCompanyByCountry GET /Private/ReportCompanyByCountryExcel GET /Private/ReportCountBookingForYear GET /Private/ReportCountBookingForYearExcel GET /Private/ReportRegisteredUser GET /Private/ReportRegisteredUserExcel GET /Private/ResentInvitation GET /Private/UserGetInfoLogIn GET /Private/UserRoleAccountManagementGetInfo GET /Public/CheckGUID GET /Public/CompanyGet GET /Public/EmployeeActiveAccount GET /Public/EndSession GET /Public/Error GET /Public/GetCurrencyCode GET /Public/GetDropdownLangVisible GET /Public/GetLabel GET /Public/GetLabelKey_ForDropDown GET /Public/GetMSCBookingLink GET /Public/GetPages_ForDropDown GET /Public/GetTranslationFile GET /Public/SearchTranslationLabels GET /Public/Test POST /Private/AdminInvitation POST /Private/BookingAdd POST /Private/BookingSearch POST /Private/BookingUpdate POST /Private/CheckUserPartnerPortal POST /Private/CompanyInsert POST /Private/CompanyUpdate POST /Private/ContactUs POST /Private/EmployeeAccountUpdate POST /Private/InsertOrUpdateProfile POST /Private/SendGenericEmail POST /Private/UserRoleAccountUpdate POST /Private/searchEmployeeAccount POST /Private/searchUserRoleAccount POST /Public/ContactUs POST /Public/PreRegistrationEmployee POST /Public/UpdateLabel
Severity: info
Fingerprint: 5733ddf49ff49cd1f3d88d603a99618638f913fc9250375e57e0e0bc3ab68518
Public Swagger UI/API detected at path: /swagger/v1/swagger.json - sample paths: DELETE /Private/AccountDelete DELETE /Private/BookingDelete GET /Private/AccountChangeStatus GET /Private/CompaniesLanguage GET /Private/CompanyList GET /Private/EmployeeSendActivationEmail GET /Private/GetAkamaiToken GET /Private/GetListCompanyType GET /Private/GetProfile GET /Private/GetUserActiveList GET /Private/GetUserFromId GET /Private/InviteGetInfo GET /Private/LanguageGetListFromOfficeId GET /Private/ReportCompany GET /Private/ReportCompanyByCountry GET /Private/ReportCompanyByCountryExcel GET /Private/ReportCountBookingForYear GET /Private/ReportCountBookingForYearExcel GET /Private/ReportRegisteredUser GET /Private/ReportRegisteredUserExcel GET /Private/ResentInvitation GET /Private/UserGetInfoLogIn GET /Private/UserRoleAccountManagementGetInfo GET /Public/CheckGUID GET /Public/CompanyGet GET /Public/EmployeeActiveAccount GET /Public/EndSession GET /Public/Error GET /Public/GetCurrencyCode GET /Public/GetDropdownLangVisible GET /Public/GetLabel GET /Public/GetLabelKey_ForDropDown GET /Public/GetMSCBookingLink GET /Public/GetPages_ForDropDown GET /Public/GetTranslationFile GET /Public/SearchTranslationLabels GET /Public/Test POST /Private/BookingAdd POST /Private/BookingSearch POST /Private/CheckUserPartnerPortal POST /Private/CompanyInsert POST /Private/ContactUs POST /Private/InsertOrUpdateProfile POST /Private/SendGenericEmail POST /Private/searchEmployeeAccount POST /Private/searchUserRoleAccount POST /Public/ContactUs POST /Public/PreRegistrationEmployee POST /Public/UpdateLabel PUT /Private/BookingUpdate PUT /Private/CompanyUpdate PUT /Private/EmployeeAccountUpdate PUT /Private/UserRoleAccountUpdate
Severity: info
Fingerprint: 5733ddf49ff49cd1aad03549c43da80118659b95776e449790a8ab0d78dd9895
Public Swagger UI/API detected at path: /swagger/index.html - sample paths: DELETE /Private/AccountDelete DELETE /Private/BookingDelete GET /Private/AccountChangeStatus GET /Private/CompaniesLanguage GET /Private/CompanyList GET /Private/EmployeeSendActivationEmail GET /Private/GetAkamaiToken GET /Private/GetListCompanyType GET /Private/GetProfile GET /Private/GetUserActiveList GET /Private/GetUserFromId GET /Private/InviteGetInfo GET /Private/LanguageGetListFromOfficeId GET /Private/ReportCompany GET /Private/ReportCompanyByCountry GET /Private/ReportCompanyByCountryExcel GET /Private/ReportCountBookingForYear GET /Private/ReportCountBookingForYearExcel GET /Private/ReportRegisteredUser GET /Private/ReportRegisteredUserExcel GET /Private/ResentInvitation GET /Private/UserGetInfoLogIn GET /Private/UserRoleAccountManagementGetInfo GET /Public/CheckGUID GET /Public/CompanyGet GET /Public/EmployeeActiveAccount GET /Public/EndSession GET /Public/Error GET /Public/GetCurrencyCode GET /Public/GetDropdownLangVisible GET /Public/GetLabel GET /Public/GetLabelKey_ForDropDown GET /Public/GetMSCBookingLink GET /Public/GetPages_ForDropDown GET /Public/GetTranslationFile GET /Public/SearchTranslationLabels GET /Public/Test POST /Private/BookingAdd POST /Private/BookingSearch POST /Private/CheckUserPartnerPortal POST /Private/CompanyInsert POST /Private/ContactUs POST /Private/InsertOrUpdateProfile POST /Private/SendGenericEmail POST /Private/searchEmployeeAccount POST /Private/searchUserRoleAccount POST /Public/ContactUs POST /Public/PreRegistrationEmployee POST /Public/UpdateLabel PUT /Private/BookingUpdate PUT /Private/CompanyUpdate PUT /Private/EmployeeAccountUpdate PUT /Private/UserRoleAccountUpdate
The following URL (usually /.git/config) is publicly accessible and is leaking source code and repository configuration.
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e34ac788
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2FmbnBnR0JUa2JWejlqOFBxb09VSzRJdmVwM1VldjBXUXUxUg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652241a5374b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2VaT0wyQTA2Wk1CR1E5aEU0N2VqaFA3MGNMZnY4NjJkekg0Ng==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652282d719d3
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2I5eVdRcHl0MENMQTdwR3ZjTTNyWVBNNkNGNVBoWTFSTWY2NQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65227c9d0967
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0NGQzIzRGdSUkFPOU9kaDJoVXc5Q1AxNXpvUWRBdTNZWTJmcA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522978f100d
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2dBdkQ2YUJNR0IwUU8zUmZIRG5SNmFySnhHcVZIeDNwZzZUMw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f9a155b6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0lBeE92aUdhYnJieDBHMTVGQlBHZUdhM1dhNHJUSDByU09FQw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522931b2f0f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2VQQXNXaUtUUnRFcHFFWUhvdWg5V21NVjduYmo2UjM3OWttSg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65227f7fab68
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1ZSVnhMQmlDcnBoc1FHY2U3cFZrbzAxUlR3blk1QjN0M1ltcw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522b6fbe22a
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2VTeUNGTUZmRXBHYjN4cGR5OTZrVjlxNlg0aTVLTDI1NTdieQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522af476449
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3JnVmZyRzA4U0VlRUpYQWxiSkU4RlJ0Mjh5UFo1ejBCcUpibQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652236849c5b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2YwdE1iUXBLVlJPYmNvQU5aNW82ejdDd3JxbEl0MDJCU2ttZQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a5ee1184
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1lsdXFJSjhHV2hRUno0c2tZcXJmcExtcXI2UWh1RzJwY3J5cg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65221605088e
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0NCbWZ5Y2pjU2NIeXJHRmFibU80V2V0NnlIMzNRRDM2MUtsdw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d9348e8b
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzZIaXFMdnU5Vm5ZOFFXakFiZmtJYWtEcE5Bd082SzNxNVNKUw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522d11f14c6
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2QzcEZ0RTR4aXhOYWhhTndNbDFkMWtjU3g0NXNiVjF3ZHlHSA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652252451c9c
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1cxRlhYMHVnYUdXVFptclJRU1NMaUtud0tzd1hKdDJleUpXOQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522ff5ce839
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX1A1UzVyYThIbGVtY1M1U0paQmowWk5pdnF1eUtQQzJYb29udA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652241774cf4
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0FYOWpuc3NmSmZEaERhQXRNTEIxYnlSNTV6U3d4NDNPaGFvUQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522134100f8
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2FUcjNNYXcwaGtCVUVOS0dZOWJUNExIQ0hQeDR2UDNUa2NUMw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652203042ea9
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3d5ZEd0cDBua2FudXVPS205YjZJVXd0dUVOM1IyYjBhUmM3VA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652229e35896
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0NsM3lqZmhTenYyZEczZzBob1BDUldST0o1V2FIcTNvVlJDTA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f65f1ce8
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0JkM1NmRkdUZW9NTUNBamtEOHlNV1ZTNUJodTF1dDBCRVJ4RQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f342b8cf
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX01tRXJsMlFBNFE5MHJscVFMTlU0MHBCcHNwcHhQbDJuZ0xucw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522b035fe86
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX0lGekh6cjA4VjU0TTZkSW1CRXlBWG9MR1hSbXJYbTJjQXdmbQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65221b4a834c
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzNFNXFkalNhUmVXWGJXaEl5TmkydDdoQUlLRkhkNTFxUHdXZA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652257dd6964
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2lYQnoySmRURXM3MElERXVjRTZJZlc4d05WN0NjazFmaU1XZA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a7bbd8a0
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzJlT09aVlE5a0swT0wwWGJjaENvaUcyWDJVdmdHQjQ4cUtOTg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522887252c7
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3lNOGxoeGxaQzczeEJwZW9JTTk2ODF0bUpXbHJxazNoTDQzYw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522af5162ce
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3RJcld1aEZ0bURnYTdna0g5UHhwUHc5T01PQTNuZjFUV29pdQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522163eb7a7
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2ltOVJDS0RpZkdFSEZoTEJoT0tyWFhSd054OVpsNzFFSkNXeA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522f8a09204
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2lGcHpxN2JOWlh4MmhmWjZHRllscmpERWt1Nm5CUjJTeXJIbQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522b0865608
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX3gwNmVrTmRncTQ1dVpxYUVrZHhrSnBRWW1WOHZPQTNTQ0pEQg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65228fa59e6f
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX21kUnl0eG10T3dTN0pvR0VLMnNxUGlhTlN4ZlJENTQ5dnc2cA==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522e25fbc7d
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzXzdaNElWYm94ZGhwYmxCdkZIS1c2a3kyV1dJbDZ5MTNVOG95bw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a65220646709d
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX21EaW9DN0h4QTh1U0NmcHMzem9STGRxSjdFT0hFYzJ5YmlvNw==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a652249b4b856
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2lJQ0htR01sNnhDV0tPVFViZm9nSkowTFFzRW4xYTBQUWd1ZQ==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522164136bd
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2JmcnFXS0c2RERPSnpNWTFjaW5QYUVSOFpBZ1dmTTBRdU9xdg==
Severity: medium
Fingerprint: 2580fa947178c88602b1737db148c044b81b03713d63bb82370a6522a2038cfc
[core] repositoryformatversion = 0 filemode = true bare = false logallrefupdates = true [remote "origin"] url = https://github.com/npr/station-service fetch = +refs/heads/*:refs/remotes/origin/* [gc] auto = 0 [http "https://github.com/"] extraheader = AUTHORIZATION: basic eC1hY2Nlc3MtdG9rZW46Z2hzX2hBV0RSRnVhM3RwWWMyOWl5ZVlhRDVydVQ0aGtoUDRTM0hyYQ==
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd18553ecf748afe318e3bc47f920a5ea0f18388b8418388b84
Public Swagger UI/API detected at path: /swagger-ui.html - sample paths:
GET /api/webhook
GET /api/webhook/{name}
POST /api/reprocess/{file-name-prefix}
POST /api/token
Severity: info
Fingerprint: 5733ddf49ff49cd1b6e67656b6e67656b6e67656b6e67656b6e67656b6e67656
Public Swagger UI/API detected at path: /swagger-ui.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd1bf890109bf890109bf890109bf890109bf890109bf890109
Public Swagger UI/API detected at path: /api-docs/swagger.json
Exposing Swagger/OpenAPI documentation is primarily a risk if your API has underlying security flaws, as it gives attackers a precise roadmap to find them.
Those detail every endpoint, parameter, and data model, making it easier to discover and exploit vulnerabilities like broken access control or injection points.
While a perfectly secure API mitigates the danger, protecting your documentation is a critical layer of defense that forces attackers to work without a map.
Severity: info
Fingerprint: 5733ddf49ff49cd12ec8532c2ec8532c2ec8532c2ec8532c2ec8532c2ec8532c
Public Swagger UI/API detected at path: /swagger/index.html
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa3ddb43bee1d037f1e956d7098828aea4d9c9275e5
GraphQL introspection enabled at /graphql Types: 671 (by kind: ENUM: 45, INPUT_OBJECT: 132, INTERFACE: 28, OBJECT: 461, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa36d6b0c2826eaa80c0a3d30aa62c671bb4a2fa523
GraphQL introspection enabled at /graphql Types: 668 (by kind: ENUM: 45, INPUT_OBJECT: 132, INTERFACE: 28, OBJECT: 458, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
GraphQL introspection is enabled.
This could leak to data leak if not properly configured.
Severity: medium
Fingerprint: c2db3a1c40d490db1a0bbaa33337941030119dd4c4df5d62a2295c631d6d31ab
GraphQL introspection enabled at /graphql Types: 665 (by kind: ENUM: 45, INPUT_OBJECT: 131, INTERFACE: 28, OBJECT: 456, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
Severity: medium
Fingerprint: c2db3a1c40d490dbf8cbe7e21d2abba504fdf2a71079c281ed0e4056b66e01e0
GraphQL introspection enabled at /graphql/api Types: 665 (by kind: ENUM: 45, INPUT_OBJECT: 131, INTERFACE: 28, OBJECT: 456, SCALAR: 5) Operations: - Query: Query | fields: adyenPaymentMethods, adyenPaymentMethodsBalance, adyenPaymentStatus, adyenRedeemedGiftcards, allowedCountriesForBilling - Mutation: Mutation | fields: addBundleProductsToCart, addConfigurableProductsToCart, addDownloadableProductsToCart, addGiftRegistryRegistrants, addProductsToCart Directives: deprecated, include, oneOf, skip (total: 4)
stage1-station.api.npr.org 38 partnership-test-live-int-api.partnership.msccruises.com 8 cloudmds.dnb.com 2 crm.omegawatches.com 2 webmaster.omegawatches.com 2 dap-racpad.rentacenter.com 1 api.amf.uat.bluecurrentservices.com 1 api.amf.dev.bluecurrentservices.com 1 api.amf.sit.bluecurrentservices.com 1 api-blue.carparts.com 1 dlsnkim.chinaielts.org 1