Why %2e Path Normalization in Spring Boot ≤2.3.0 Lets Attackers Bypass Authentication
This article explains how Spring Boot versions up to 2.3.0.RELEASE normalize URLs containing the %2e sequence, causing servlet path handling that can be exploited to bypass authentication, and shows why the behavior changes in later releases.
