Get ahead
VMware offers training and certification to turbo-charge your progress.
Learn moreUsing "**"
as a pattern in Spring Security configuration with the mvcRequestMatcher
creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
The following Spring Framework versions contain fixes for this vulnerability:
This vulnerability was discovered internally.
To report a security vulnerability for a project within the Spring portfolio, see the Security Policy