In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily be misconfigured to be bypassed on some servlet containers. Applications using RegexRequestMatcher with `.` in the regular expression are possibly vulnerable to an authorization bypass.
https://github.com/lr-elaina520/cve-analysis
https://github.com/berinle/spring-enterprise-remediation-demo
https://github.com/heyjerrybecker/seevie-pri
https://github.com/banaeye/cvetest
https://github.com/wyqsgy/vulnark
https://github.com/dev-osama-alharbi/spring-CVEs
https://github.com/he-ewo/CVE-2022-22978
https://github.com/BoB13-Opensource-Contribution-Team9/CVE-2022-22978
https://github.com/Drun1baby/CVE-Reproduction-And-Analysis
https://github.com/Whoopsunix/PPPVULNS
https://github.com/StarCrossPortal/VulnsDB
https://github.com/Lay0us1/CVE-2022-32532
https://github.com/DeEpinGh0st/CVE-2022-22978
https://github.com/advisories/GHSA-hh32-7344-cg2f