BCryptPasswordEncoder.matches(CharSequence,String) will incorrectly return true for passwords larger than 72 characters as long as the first 72 characters are the same.
https://www.securityweek.com/high-severity-vulnerabilities-patched-by-cisco-atlassian/