I have a Spring MVC (5.0.8.RELEASE) application and a recent security scan indicates that it has \"Path-Based Vulnerability\". Here is the controller:
@RequestMa
Because spring support suffix ".*" default. /person is also mapped to /person.* /person.xml or /person.pdf or /person.any is also mapped. - To completely disable the use of file extensions, you must set both of these:
.useSuffixPatternMatching(false)
.favorPathExtension(false)
https://docs.spring.io/spring/docs/current/spring-framework-reference/web.html#mvc-ann-requestmapping-suffix-pattern-match