Using "**" as a pattern in Spring Security configuration for WebFlux creates a mismatch in pattern matching between Spring Security and Spring WebFlux, and the potential for a security bypass.
https://github.com/mayank1120/cve-fix-checker
https://github.com/hotblac/cve-2023-34034